FR
live
Security Critical CVSS 9.8

CISA Adds Langflow (CVSS 9.8), N-central, and Apache Tomcat to KEV — Three Flaws Under Active Exploitation

On August 5, 2026, CISA added three critical vulnerabilities to its KEV catalog: CVE-2026-9198 in IBM Langflow (CVSS 9.8), CVE-2026-18576 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. Federal agencies must patch immediately.

Three patch cables disconnected from a server rack patch panel, their amber-lit ports glowing in the dark

August 5, 2026. The CISA (Cybersecurity and Infrastructure Security Agency) added three new vulnerabilities to its KEV (Known Exploited Vulnerabilities) catalog, confirming active exploitation by threat actors. The three flaws affect IBM Langflow (CVSS 9.8), N-able N-central, and Apache Tomcat — three products deployed in radically different contexts, each critical to the organizations that rely on them.

U.S. federal agencies have until August 7, 2026 to apply mitigations. For private-sector organizations, a CVE’s appearance in the KEV catalog is the signal that transforms a patch recommendation into an operational obligation.

CVE-2026-9198 — Langflow: Unauthenticated RCE at 9.8

The most severe of the three is CVE-2026-9198, affecting the visual IBM Langflow framework — a drag-and-drop AI agent builder that has become ubiquitous in LLMOps pipelines since its breakout in 2025.

The CVSS 9.8 (Critical) score reflects the attack’s severity: an unauthenticated attacker can achieve remote code execution (RCE) on default Langflow deployments. The exploit chains two API endpoints: the first bypasses authentication, the second executes arbitrary code.

By late July 2026, multiple fully functional Proof-of-Concept (PoC) exploits had surfaced publicly, complete with step-by-step exploitation instructions. The barrier to entry for attackers has dropped to zero.

This is the second critical Langflow vulnerability actively exploited in two weeks. On July 17, 2026, CISA had already flagged CVE-2026-0770, another RCE with root privileges on the same product. Langflow’s maintainers have patched both flaws, but the pattern is concerning: a young product backed by IBM’s ecosystem is now attracting threat actor attention at scale.

If you deploy Langflow, the verification is immediate: is your version newer than the patch for both CVEs? If you can’t patch within the hour, cut public exposure to the Langflow interface — an upstream reverse proxy with authentication blocks the attack vector even if the underlying application remains vulnerable.

CVE-2026-18576 — N-central: The Patch That Wasn’t Enough

CVE-2026-18576 affects the N-able N-central remote monitoring and management platform, a tool deployed by MSPs (Managed Service Providers) to administer their clients’ IT estates. The flaw allows an attacker to hijack administrative accounts without prior authentication.

The timeline of this CVE illustrates a recurring incident response problem: the initial patch was insufficient. N-able shipped a fix for the vulnerability, but attackers found a new bypass method. On August 1, 2026, the vendor warned customers that the flaw was being actively exploited via the new variant, which received the same CVE identifier.

An emergency hotfix was released on Sunday, August 3, 2026, addressing all N-central versions prior to 2026.3. N-able is urging customers to apply it immediately.

The impact for MSPs is systemic: an attacker who compromises an MSP’s N-central instance gains administrative access to every managed client. This is the supply chain attack by proxy — the target isn’t the MSP itself, but all its clients, accessible from a single administrative point.

CVE-2026-34486 — Apache Tomcat: The Incomplete Fix for a 9.8

CVE-2026-34486 (CVSS 7.5) is a textbook case of an incomplete patch. It stems from the insufficient fix for CVE-2026-29146, a critical vulnerability rated CVSS 9.8 described as the missing encryption of sensitive data in Apache Tomcat.

On July 30, 2026, researchers at Palo Alto Networks Unit 42 observed a Chinese-speaking threat actor attempting to exploit CVE-2026-34486 in a manual campaign aimed at deploying reverse shells on nine Apache Tomcat servers. The precise targeting and manual nature of the operation suggest a determined adversary — not an automated scan.

Apache Tomcat is the most widely deployed Java application server in the world, present in millions of organizations. The combination of an incomplete patch and manual, targeted exploitation makes this CVE especially dangerous for organizations that applied the initial fix without verifying its real-world effectiveness.

CISA notes that it has no confirmation of these flaws being used in ransomware campaigns, but the KEV catalog’s history shows that today’s absence of confirmation is no guarantee for tomorrow — ransomware operators routinely adopt KEV vulnerabilities within weeks.

The KEV as an Operational Barometer

The CISA KEV catalog is not a threat intelligence bulletin — it’s a binding operational directive (BOD 22-01) for U.S. federal agencies. But its value extends beyond government: it is the only public indicator that separates theoretical CVEs from exploited CVEs, and it has become the de facto standard for patch prioritization in private-sector organizations.

In 2026, the KEV has ingested over 200 vulnerabilities, with a growing share tied to AI and automation tools — Langflow being the latest example. The threat perimeter is shifting from traditional web servers to emerging platforms.

Verdict

If your organization runs IBM Langflow, N-able N-central, or Apache Tomcat on a version predating the August 5, 2026 fixes, you are directly exposed to active, documented exploits. The prioritization is unambiguous:

  1. Langflow — patch or cut public exposure immediately (CVSS 9.8, public PoCs available).
  2. N-central — apply hotfix 2026.3; if you’re an MSP, this is your top priority — your clients’ security depends on your response time.
  3. Apache Tomcat — verify your version addresses both CVEs (CVE-2026-29146 and CVE-2026-34486) — a partial patch does not protect you.

Three KEV additions in a single day is a heightened vigilance signal. August 2026 is shaping up to be a heavy month for security teams.

References

  • BleepingComputer, « CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws », August 5, 2026, by Ionut Ilascu.
  • CISA, « Known Exploited Vulnerabilities Catalog », accessed August 5, 2026.
  • Palo Alto Networks Unit 42, report on CVE-2026-34486 exploitation, July 30, 2026.
  • N-able, N-central security advisory, August 1, 2026.
  • IBM, Langflow security advisory CVE-2026-9198, July 2026.
cve

Linked vulnerabilities

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

TP-Link Patches 15 Omada ZTP Flaws After Black Hat Disclosure

Forescout Vedere Labs presented 15 zero-touch provisioning vulnerabilities in TP-Link Omada at Black Hat USA, including 11 CVEs. SMBs deploying network gear via ZTP must patch immediately and rotate all exposed secrets.

← Back to the feed

Type at least two characters.

navigate open esc dismiss