CVE Tools

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The Hacker NewsBy The Hacker News

Reported exploitedLangflowknaitheApache Tomcat

Our summary

On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These include a critical remote code execution (RCE) flaw in Langflow (CVE-2026-9198, CVSS 9.8), an encryption bypass in Apache Tomcat (CVE-2026-34486, CVSS 7.5), and an authentication bypass in N-able N-central (CVE-2026-18556, CVSS 8.2). Attackers are exploiting these flaws, with some linked to a Chinese-speaking threat actor using AI-powered tools like Hermes Agent and DeepSeek to automate attacks. Federal agencies have until August 7, 2026, to apply available patches.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store