The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat. The agency highlighted the critical nature of these flaws, urging immediate attention from relevant sectors.
Langflow OSS Vulnerability Details
Identified as CVE-2026-9198 with a CVSS score of 9.8, the Langflow OSS vulnerability allows attackers to execute remote code. It involves two API endpoints that can be chained together for exploitation. Disclosed on July 17, IBM has since released patches in version 1.10.1, noting that default deployments were particularly at risk.
The vulnerability arises from two separate issues: an endpoint issuing superuser tokens to unauthorized users and a validation endpoint executing arbitrary Python code. Attackers can exploit these by first obtaining the superuser token and then submitting harmful code. A proof-of-concept for this flaw was made public shortly after its disclosure, and CISA included it in its Known Exploited Vulnerabilities (KEV) catalog on August 4.
N-central Vulnerability Insights
The N-able N-central vulnerability, tracked as CVE-2026-18556 with a CVSS score of 7.4, involves an authentication bypass. It allowed attackers to gain unauthorized access to systems managed through N-central’s remote monitoring and management platform. Despite an initial fix, exploitation increased, leading N-able to release a hotfix and track the issue as CVE-2026-18577, both now listed in CISA’s KEV.
This vulnerability was exploited as a zero-day, granting administrative access and posing significant security risks, particularly as activity surged towards the end of July.
Apache Tomcat Encryption Bypass
The third vulnerability affects Apache Tomcat and is identified as CVE-2026-34486, with a CVSS score of 7.5. It involves an EncryptInterceptor bypass, initially introduced in March and patched in April. The flaw allowed unauthorized remote code execution by improperly handling encrypted messages within Tomcat clusters.
StrigaAI, credited with discovering the bug, explained that the patch altered a single line of code, shifting the encryption from fail-closed to fail-open, thereby exposing systems to potential attacks. This vulnerability has been exploited by Chinese actors using the Snowlight malware, as noted by SOCRadar and Palo Alto Networks.
Implications and Recommendations
CISA has mandated federal agencies to address these vulnerabilities by August 7, in accordance with BOD 26-04. The agency’s directive underscores the urgent need for patching to prevent potential breaches and safeguard data integrity across affected platforms.
These vulnerabilities highlight the critical importance of timely updates and vigilant security practices to counteract possible exploitation by threat actors.
