CVE Tools

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

BleepingComputerBy Ionut Ilascu

Reported exploitedLangflowN-central

Our summary

Federal agencies have until July 7 to address three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, as highlighted by CISA. The most severe flaw, CVE-2026-9198 in IBM's Langflow, enables unauthenticated remote code execution with a CVSS score of 9.8. A related vulnerability, CVE-2026-0770, also allows RCE with root privileges and has already seen public PoCs. Meanwhile, a patched but re-exploitable flaw in N-central (CVE-2026-18576) permits unauthorized account takeover, while Apache Tomcat faces an incomplete fix for another issue (CVE-2026-34486). All three vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities list.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store