CVE-2026-9198 — a flaw in IBM’s Langflow rated 9.8 out of 10 — permits an unauthenticated attacker to execute code remotely on default Langflow deployments by chaining two API endpoints to bypass login.
IBM Langflow’s CVE-2026-9198 and the recent PoCs
CISA flagged CVE-2026-9198 as the most severe of the three tracked flaws, giving it a critical 9.8/10 rating. The vulnerability “allows an unauthenticated attacker to execute remotely on default Langflow deployments by chaining two API endpoints to bypass login and run code,” the advisory states. In late July, multiple fully functional proof-of-concept (PoC) exploits for CVE-2026-9198 appeared in the public space; those PoCs included complete instructions on how the vulnerability can be leveraged.
The advisory also noted that this is not the first Langflow issue under active exploitation: two weeks ago CISA issued an alert for another critical Langflow vulnerability, CVE-2026-0770, which was being used in attacks to gain remote code execution with root privileges.
N-able’s N-central (CVE-2026-18576): patch, bypass, emergency hotfix
The flaw in N-able’s remote monitoring and management product N-central is tracked as CVE-2026-18576. According to the bulletin, the vulnerability “allows attackers to hijack administrative accounts without authentication.” The vendor issued a patch, but CISA reported the fix was insufficient and threat actors found a new way to exploit the product.
N-able warned customers on August 1st that hackers were actively exploiting the vulnerability identified as CVE-2026-18576. In response, the company released an emergency hotfix “on Sunday” and urged customers to install it. The vendor said the flaw affected “all versions of N-central before 2026.3.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildApache Tomcat CVE-2026-34486 and Unit 42’s July 30 report
The Apache Tomcat issue, tracked as CVE-2026-34486, carries a high-severity score of 7.5 and, according to CISA, stems from an incomplete fix for CVE-2026-29146. The earlier CVE-2026-29146 was described as a critical vulnerability with a severity rating of 9.8 and characterized in the advisory as “the missing encryption of sensitive data.”
On July 30, researchers at Palo Alto Networks Unit 42 reported that a Chinese-speaking threat actor attempted to exploit CVE-2026-34486 in a manual campaign to plant reverse shells on nine Apache Tomcat servers. CISA confirmed that threat actors are leveraging the Tomcat flaw alongside the Langflow and N-central vulnerabilities.
CISA’s directive, KEV listing, and what the agency disclosed
CISA confirmed it has added all three vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). The agency gave federal agencies a short mitigation window: it is “giving federal agencies three days to mitigate vulnerabilities” in the three products and “has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, July 7th,” the advisory says. CISA also stated it did not share what types of attacks are leveraging the flaws, noting that “it is unknown if they are used in ransomware campaigns.”
What this means for federal agencies, security teams, and affected enterprises
- Federal agencies: CISA’s order requires agencies to apply available mitigations within the agency’s stated timeframes — the advisory specifically directs agencies to implement mitigations and lists the three targeted products (Langflow, N-central, Apache Tomcat) as added to KEV.
- Security teams: Teams operating Langflow should treat CVE-2026-9198 as a critical, actively exploited risk, especially given the late-July PoCs containing complete exploit instructions; operators of N-central must install N-able’s emergency hotfix (the vendor said the flaw impacts all versions before 2026.3); Tomcat administrators should be alert to exploitation tied to an incomplete prior fix and Unit 42’s report of reverse-shell attempts on July 30.
- Affected enterprises and procurement leaders: The advisory signals both the speed of public PoCs and the limits of an initial vendor patch — N-able’s earlier fix was judged insufficient — underscoring a need to track vendor advisories, emergency hotfixes, and version impact (for example, N-central versions before 2026.3).
The facts in the advisory sketch a short, dangerous sequence: a critical Langflow flaw with public PoCs, an N-central vulnerability that outpaced an initial vendor patch, and an Apache Tomcat issue tied to an incomplete fix and observed reverse-shell attempts. CISA’s KEV additions and rapid mitigation order underline the urgency, even as the agency acknowledged it has not attributed the attack types or confirmed links to ransomware campaigns — a concrete gap the record leaves open.
Source: BleepingComputer — CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws




