CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CISA Adds Langflow, Apache Tomcat, and N-able N-central Flaws to KEV Catalog Amid Active Exploitation

August 5, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. The flaws include a critical remote code execution vulnerability in Langflow (CVE-2026-9198), an encryption bypass in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556).

CVE-2026-9198 is a code injection vulnerability in Langflow, an open-source AI application development platform, allowing unauthenticated attackers to achieve full remote code execution on default deployments. It was fixed in version 1.10.1 released in July 2026.

CVE-2026-34486 is a missing encryption of sensitive data vulnerability in Apache Tomcat that allows bypass of the EncryptInterceptor cluster component. It was fixed in versions 11.0.21, 10.1.54, and 9.0.117 released in April 2026. Exploitation has been attributed to an AI-enabled autonomous hacking campaign by a Chinese-speaking threat actor using aliases knaithe and KnYuan, based in Zhuhai, China. The actor leveraged DeepSeek via the Hermes Agent framework to target internet-exposed devices, conducting autonomous research to identify high-value vulnerabilities when initial attempts failed.

CVE-2026-18556 is an authentication bypass in N-able N-central, with an incomplete fix leading to a follow-up patch tracked as CVE-2026-18577. Both are now listed in the KEV catalog.

Palo Alto Networks Unit 42 reported that the threat actor attempted to exploit over 460 targets using a mix of autonomous and manual techniques, allowing DeepSeek to narrow targeting scope to conserve AI compute. Federal Civilian Executive Branch (FCEB) agencies must apply fixes by August 7, 2026.

CVEs: CVE-2026-9198, CVE-2026-34486, CVE-2026-18556, CVE-2026-18577, CVE-2026-33017, CVE-2026-3055, CVE-2026-39987, CVE-2026-33824, CVE-2026-50522

Attack groups: knaithe, KnYuan

Companies: CISA, Palo Alto Networks Unit 42, N-able, Apache Software Foundation, Langflow

Products: Langflow, Apache Tomcat, N-able N-central, DeepSeek, Hermes Agent, Citrix NetScaler, Marimo, IKE VPN