Critical

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The Hacker News
Actively Exploited

Overview

On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating that they are being actively exploited. The most severe of these is CVE-2026-9198, a code injection flaw in Langflow that allows attackers to execute remote code without authentication, scoring 9.8 on the CVSS scale. Additionally, vulnerabilities in Tomcat and N-central were also flagged. These flaws pose significant risks to users and organizations relying on these platforms, as they could lead to unauthorized access and control over systems. Companies using these products should take immediate action to mitigate the risks associated with these vulnerabilities.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Langflow, Tomcat, N-central
  • Action Required: Organizations should apply any available patches for Langflow, Tomcat, and N-central as soon as possible.
  • Timeline: Disclosed on August 5, 2026

Original Article Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote

Impact

Langflow, Tomcat, N-central

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on August 5, 2026

Remediation

Organizations should apply any available patches for Langflow, Tomcat, and N-central as soon as possible. Specific patch numbers or versions were not mentioned, but users should consult their respective vendor documentation for updates. In general, users should also implement proper access controls and monitor systems for any unusual activity.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, RCE.

Related Coverage

Silent Patches Don’t Stop Attackers—They Blind Defenders

SecurityWeek

The article discusses the issue of silent patches, which are updates made to software to fix vulnerabilities without publicly disclosing the details. While these patches can help secure systems, they also create a problem for defenders. Attackers can exploit these vulnerabilities without defenders knowing the full context of the risks they face. This lack of transparency can lead to misprioritization of security efforts, leaving organizations vulnerable. The piece emphasizes the need for better communication about vulnerabilities and updates to ensure that defenders have the information they need to protect against potential exploits.

Aug 25, 2026

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

Infosecurity Magazine

ReliaQuest has addressed a recent social engineering attack associated with the hacking group ShinyHunters. The company clarified that while there were attempts to compromise its systems, the attackers did not succeed in breaching their defenses. This incident serves as a reminder of the growing threat posed by social engineering tactics, where attackers manipulate individuals into divulging confidential information. Despite the denial of a successful compromise, the event raises concerns about the effectiveness of security measures and the importance of employee awareness training. Companies must remain vigilant against such tactics to protect sensitive data and maintain trust with their clients.

Aug 25, 2026

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

Infosecurity Magazine

The U.S. government has imposed sanctions on several individuals linked to the Mabna Institute, a hacking group based in Iran known for cyber-attacks. This group has been involved in various hacking activities, including stealing data from universities and businesses around the world. The sanctions target the group's members to disrupt their operations and deter similar actions in the future. By penalizing these individuals, the U.S. aims to hold them accountable for their cyber activities that threaten both national security and economic interests. This move also signals to other state-sponsored hacking groups that there are consequences for such cyber crimes.

Aug 25, 2026

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in Oracle's HTTP Server and Weblogic Server Proxy Plug-in to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-21962, carries a maximum severity score of 10.0, indicating it is a critical risk for users. The vulnerability allows unauthenticated attackers to exploit the affected systems, which could potentially lead to unauthorized access and control. Organizations using these Oracle products should take immediate action to assess their systems and implement necessary security measures to mitigate this risk. The inclusion in CISA's catalog suggests that this vulnerability is being actively targeted by malicious actors, making swift remediation essential.

Aug 25, 2026

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News

Attackers are exploiting two serious vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing unauthorized users to log in as any WordPress user, including those with administrative privileges. These vulnerabilities, identified as CVE-2026-61979, have a CVSS score of 8.1, indicating a high severity level. This situation puts numerous WordPress sites at risk, as it could enable attackers to gain complete control over these sites without needing valid credentials. The vulnerabilities were disclosed by Patchstack, underscoring the need for site administrators to take immediate action. Promptly addressing these flaws is crucial to prevent unauthorized access and potential data breaches.

Aug 25, 2026

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff

SecurityWeek

Taiwan has charged nine individuals, including staff from Nvidia and Super Micro, for illegally exporting AI servers to China. These exports involved advanced semiconductors that are primarily manufactured in Taiwan, which are crucial for AI infrastructure. The Taiwanese government is taking a strong stance against these actions, reflecting ongoing tensions between the U.S. and China over technology and trade. This case highlights the sensitive nature of semiconductor technology and its role in global competition. The individuals involved face serious legal repercussions, emphasizing the importance of compliance with export regulations in the tech industry.

Aug 25, 2026