Technology News

CISA Flags Langflow RCE, Tomcat, and N‑Central Flaws as Actively Exploited

Three critical vulnerabilities—Langflow, Tomcat, and SolarWinds N‑Central—have been confirmed as actively exploited in the wild, prompting CISA to add them to its Known Exploited Vulnerabilities catalog on August 5 2026.

On August 5, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild.

The first is CVE-2026-9198, a code‑injection flaw in the Langflow framework that permits unauthenticated attackers to execute arbitrary code with full system privileges.

The flaw, rated CVSS 9.8, allows attackers to craft a specially‑formatted request that bypasses the framework’s authentication layer and injects shell commands into the execution context.

A second entry, CVE-2026-9200, affects Apache Tomcat 9.x and 10.x versions, enabling remote code execution via a malformed HTTP POST request that exploits an unchecked parameter in the Tomcat connector.

The Tomcat vulnerability, scored 9.3, has already been used in several high‑profile phishing campaigns where attackers drop a malicious WAR file that is then executed on the target server.

The third CVE, CVE-2026-9201, targets the SolarWinds N‑Central network‑management platform, allowing unauthenticated attackers to read and modify configuration files, effectively granting full administrative control.

The N‑Central flaw, with a CVSS rating of 9.1, has been observed in the wild where attackers used it to pivot into corporate networks and exfiltrate data.

In a public statement, CISA urged all organizations that run the affected software to apply the vendor patches immediately and to monitor logs for signs of exploitation.

The agency also recommended that administrators enable application‑level firewalls and restrict network access to the vulnerable endpoints until the patches are deployed.

Security researchers have confirmed that the exploitation code is available on several underground forums, underscoring the urgency of the mitigation steps.

CISA Flags Langflow RCE, Tomcat, and N‑Central Flaws as Actively Exploited

On August 5, 2026, CISA added three vulnerabilities to its Known Exploit…

On August 5, 2026, CISA added three vulnerabilities to its Known Exploit…

On August 5, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild.

The first is CVE-2026-9198, a code‑injection flaw in the Langflow framework that permits unauthenticated attackers to execute arbitrary code with full system privileges.

The flaw, rated CVSS 9.8, allows attackers to craft a specially‑formatte…

The flaw, rated CVSS 9.8, allows attackers to craft a specially‑formatte…

The flaw, rated CVSS 9.8, allows attackers to craft a specially‑formatted request that bypasses the framework’s authentication layer and injects shell commands into the execution context.

A second entry, CVE-2026-9200, affects Apache Tomcat 9.x and 10.x versions, enabling remote code execution via a malformed HTTP POST request that exploits an unchecked parameter in the Tomcat connector.

The Tomcat vulnerability, scored 9.3, has already been used in several h…

The Tomcat vulnerability, scored 9.3, has already been used in several h…

The Tomcat vulnerability, scored 9.3, has already been used in several high‑profile phishing campaigns where attackers drop a malicious WAR file that is then executed on the target server.

The third CVE, CVE-2026-9201, targets the SolarWinds N‑Central network‑management platform, allowing unauthenticated attackers to read and modify configuration files, effectively granting full administrative control.

The N‑Central flaw, with a CVSS rating of 9.1, has been observed in the…

The N‑Central flaw, with a CVSS rating of 9.1, has been observed in the…

The N‑Central flaw, with a CVSS rating of 9.1, has been observed in the wild where attackers used it to pivot into corporate networks and exfiltrate data.

In a public statement, CISA urged all organizations that run the affected software to apply the vendor patches immediately and to monitor logs for signs of exploitation.

The agency also recommended that administrators enable application‑level…

The agency also recommended that administrators enable application‑level…

The agency also recommended that administrators enable application‑level firewalls and restrict network access to the vulnerable endpoints until the patches are deployed.

Security researchers have confirmed that the exploitation code is available on several underground forums, underscoring the urgency of the mitigation steps.