CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Reported exploitedLangflowN-centralOur summary
Federal agencies have until July 7 to address three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, as highlighted by CISA. The most severe flaw, CVE-2026-9198 in IBM's Langflow, enables unauthenticated remote code execution with a CVSS score of 9.8. A related vulnerability, CVE-2026-0770, also allows RCE with root privileges and has already seen public PoCs. Meanwhile, a patched but re-exploitable flaw in N-central (CVE-2026-18576) permits unauthorized account takeover, while Apache Tomcat faces an incomplete fix for another issue (CVE-2026-34486). All three vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities list.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.