CISA Adds Langflow, Tomcat and N-central Flaws to KEV

CISA on August 5 added three actively exploited vulnerabilities to its KEV catalog, including a critical Langflow RCE and an Apache Tomcat encryption bypass linked to a DeepSeek-driven autonomous hacking campaign.

CISA Adds Langflow, Tomcat and N-central Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on August 5, 2026 added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, flagging critical flaws in the popular open-source AI framework Langflow, in Apache Tomcat, and in N-able N-central remote monitoring software. Federal Civilian Executive Branch agencies have until August 7 to patch.

Three critical flaws under active exploitation

The new KEV entries are CVE-2026-9198 (CVSS 9.8), an unauthenticated remote code execution flaw in Langflow fixed in July with version 1.10.1; CVE-2026-34486 (CVSS 7.5), a missing-encryption bug in Apache Tomcat that bypasses the EncryptInterceptor cluster-messaging component and was patched in Tomcat 11.0.21, 10.1.54 and 9.0.117 in April; and CVE-2026-18556 (CVSS 8.2), an authentication bypass in N-able N-central whose incomplete fix prompted a fresh patch tracked as CVE-2026-18577 also on the KEV list.

Apache Software Foundation logo

DeepSeek-driven agent behind Tomcat attacks

Palo Alto Networks Unit 42 has attributed exploitation of the Tomcat flaw to an autonomous AI-enabled hacking campaign run by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan from Zhuhai, China. The operator drove DeepSeek through the Hermes Agent framework, using the LLM as an offensive orchestrator that identified targets, pivoted to higher-value flaws in n8n and Marimo when initial Langflow attempts failed, and manually chained known vulnerabilities in Citrix NetScaler, Apache Tomcat and IKE VPN. Unit 42 said the actor attempted more than 460 targets and allowed DeepSeek to narrow the target list to conserve inference compute.

Langflow keeps drawing fire

The Langflow KEV entry follows a run of vulnerabilities in the AI agent framework earlier this summer. Prior Langflow RCE flaws have been used to deploy Monero cryptominers and were weaponized in the EncForge ransomware campaign, and CVE-2026-33017 was cited in a separate agentic-attack report last month. The pattern echoes JadePuffer's use of an earlier Langflow flaw for autonomous ransomware.

N-able rush patches after incomplete fix

The N-central additions arrive days after CISA added CVE-2026-18577, the follow-on patch, to the KEV catalog earlier this week. MSPs relying on N-central for endpoint management have been urged by Huntress and CISA to apply the vendor's hardening steps immediately.

Reporting based on coverage from The Hacker News, CISA, Palo Alto Networks Unit 42 and Apache lists.

Category: Cyber Security

Tags: AI Cybersecurity artificial intelligence CVE ransomware

Related Articles