On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added three vulnerabilities — including CVE-2026-9198 — to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation in the wild.
CVE-2026-9198: Langflow full remote code execution
CISA flagged CVE-2026-9198 (CVSS score: 9.8), a code injection vulnerability in Langflow that "allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments." The vulnerability was fixed in July 2026 by Langflow maintainers in version 1.10.1. The advisory notes there are currently no public details on how CVE-2026-9198 is being exploited, though it also records that security defects in the open-source artificial intelligence (AI) application development platform "have been repeatedly weaponized by bad actors in recent months."
CVE-2026-34486: Apache Tomcat EncryptInterceptor bypass and AI-enabled attacks
CISA added CVE-2026-34486 (CVS score: 7.5), described as a missing encryption of sensitive data vulnerability in Apache Tomcat that permits a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. Apache issued fixes in April 2026 in versions 11.0.21, 10.1.54, and 9.0.117.
The exploitation of CVE-2026-34486 has been attributed in the advisory to "an AI-enabled autonomous hacking campaign" operated by a Chinese-speaking threat actor using the aliases knaithe and KnYuan. That actor — which the advisory says is based in Zhuhai, China — is reported to have leveraged DeepSeek, via the Hermes Agent framework, as an offensive operator to target internet-exposed devices.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble →N-able N-central: authentication bypass, an incomplete fix, and two tracked CVEs
CISA also added CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central. The advisory calls out that an incomplete fix for the issue prompted N‑able to issue a fresh patch, which is tracked as CVE-2026-18577 (CVSS score: 8.2). While CVE-2026-18577 was placed in the KEV catalog on Monday, CISA's August 5 update signals that both CVE-2026-18556 and CVE-2026-18577 are being exploited by threat actors.
Palo Alto Networks Unit 42: autonomous and manual tradecraft in the campaign
Palo Alto Networks Unit 42 provided incident details cited by CISA showing the campaign blended autonomous AI-driven operators and manual follow-up operations. Unit 42 said the actor "attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques." Unit 42 further observed: "What's interesting is that the actor appeared to allow DeepSeek to narrow the targeting scope, likely to conserve AI compute."
The advisory describes how the AI operator behaved when initial attempts failed: when exploitation attempts against another Langflow flaw (CVE-2026-33017, CVSS 9.8) were blocked by restrictive target configurations, the AI agent "conducted autonomous research to identify other higher-value vulnerabilities, including flaws in n8n, to find a way in." Separately, the adversary carried out manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
What this means for Federal Civilian Executive Branch agencies, N-able, and Langflow maintainers
- Federal Civilian Executive Branch (FCEB) agencies: CISA set a clear and near-term operational requirement — agencies "have until August 7, 2026, to apply the necessary fixes and safeguard their networks from active threats." That deadline places immediate pressure on federal patch and asset teams to inventory exposures and deploy the published fixes.
- N-able: The vendor has already issued a fresh patch after an incomplete remediation. Both tracked CVEs for N-central (CVE-2026-18556 and CVE-2026-18577) are now in the KEV catalog and are reported as being actively exploited, which raises urgency for customers to validate patch installation and authentication controls.
- Langflow maintainers and users: Langflow released a fix in July 2026 (version 1.10.1) for CVE-2026-9198, but CISA notes repeated weaponization of defects in the platform and records that details of active exploitation for CVE-2026-9198 are not yet available; maintainers and deployments should confirm version levels and hunting visibility.
The entry of these three flaws into CISA's Known Exploited Vulnerabilities catalog on August 5 underscores two facts recorded in the advisory: attackers are combining AI-enabled autonomous tooling with hands-on-keyboard follow-up, and federal agencies face a narrow compliance window to patch known-critical exposures. Unit 42's account — including the actor's use of DeepSeek via Hermes Agent and its reported targeting of more than 460 systems — frames the activity as sustained and adaptive, while the parallel tracking of two N-central CVEs shows the operational consequences of incomplete fixes. Federal agencies, vendors, and operators who have not yet applied the published updates are the named parties facing the most immediate risk.
https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html




