discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CISA Warns of Hackers Exploiting Langflow, N-central, Apache Tomcat Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of hackers exploiting vulnerabilities in IBM Langflow, N-central, and Apache Tomcat. The agency has given federal agencies three days to mitigate the vulnerabilities.

By Ionut Ilascu·Aug 5·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

CISA Warns of Hackers Exploiting Langflow, N-central, Apache Tomcat Flaws
Image: bleepingcomputer.com

CISA has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, August 7th. The vulnerabilities allow hackers to execute remote code execution with root privileges.

Why it matters

The exploitation of these vulnerabilities poses a significant threat to federal agencies and their sensitive data. It is essential for these agencies to take immediate action to mitigate the risks.

Imagine you have a super powerful computer that can do lots of things, but someone can hack into it and do bad things without needing a password. That's what's happening with some computers that use Langflow, N-central, and Apache Tomcat. The people in charge of these computers need to fix the problems so hackers can't get in.

Analysis

A Critical Threat to Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies regarding the exploitation of vulnerabilities in IBM Langflow, N-central, and Apache Tomcat. The agency has given federal agencies three days to mitigate the vulnerabilities, which pose a significant threat to their sensitive data.

The Langflow vulnerability, tracked as CVE-2026-9198, is the most severe, with a critical rating of 9.8 out of 10. It allows an unauthenticated attacker to execute remotely on default Langflow deployments by chaining two API endpoints to bypass login and run code. In late July, multiple fully functional proof-of-concept (PoC) exploits for CVE-2026-9198 emerged in the public space, with complete instructions on how they can be leveraged.

The N-central vulnerability, identified as CVE-2026-18576, allows attackers to hijack administrative accounts without authentication. The flaw received a high-severity rating and has been patched by the vendor. However, the fix was insufficient, and threat actors found a new way to exploit it. N-able warned customers on August 1st that hackers were actively exploiting the new vulnerability.

The Apache Tomcat vulnerability, tracked as CVE-2026-34486, has a high-severity score of 7.5. It stems from an incomplete fix for CVE-2026-29146, a critical vulnerability with a severity rating of 9.8 that is described as the missing encryption of sensitive data. On July 30, researchers at Palo Alto Networks Unit 42 reported that a Chinese-speaking threat actor tried to exploit the CVE-2026-34486 vulnerability in a manual campaign to plant reverse shells on nine Apache Tomcat servers.

CISA has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, August 7th. The agency has not shared what types of attacks are leveraging these vulnerabilities, noting that it is unknown if they are used in ransomware campaigns. However, the agency has added them to its catalog of Known Exploited Vulnerabilities (KEV).

The exploitation of these vulnerabilities poses a significant threat to federal agencies and their sensitive data. It is essential for these agencies to take immediate action to mitigate the risks. The CISA warning serves as a reminder of the importance of regular security updates and patches to prevent such vulnerabilities from being exploited.

Key points

  • CISA has warned federal agencies of hackers exploiting vulnerabilities in IBM Langflow, N-central, and Apache Tomcat.
  • The agency has given federal agencies three days to mitigate the vulnerabilities.
  • The Langflow vulnerability, tracked as CVE-2026-9198, is the most severe, with a critical rating of 9.8 out of 10.
  • The N-central vulnerability, identified as CVE-2026-18576, allows attackers to hijack administrative accounts without authentication.
  • The Apache Tomcat vulnerability, tracked as CVE-2026-34486, has a high-severity score of 7.5.
The Upside

If federal agencies take immediate action to mitigate the vulnerabilities, they can prevent hackers from exploiting them and protect their sensitive data. This will also help to prevent potential ransomware campaigns.

The Downside

If federal agencies fail to take immediate action to mitigate the vulnerabilities, hackers may be able to exploit them and gain access to sensitive data. This could lead to significant consequences, including data breaches and potential ransomware campaigns.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritylangflown-centralapache-tomcatcisavulnerabilitiesexploitation

Author

Ionut Ilascu

Intelligence analysis by

Llama

Published

Aug 5, 2026

Source

bleepingcomputer.com

Share

Topics

securitylangflown-centralapache-tomcatcisavulnerabilitiesexploitation

Related

More from this desk

Aug 6·thehackernews.com

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Vulnerability in Chinese-made routers from Zbtlink detected with backdoors that can be remotely accessed without authentication.

Aug 6·thehackernews.com

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.

Aug 6·thehackernews.com

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at le…

Aug 5·wired.com

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

A security researcher, Vangelis Stykas, gained access to North Korean systems and found evidence of 1,640 companies across 57 countries being impacted by the country's hacking operations. Among these, around 700 to 800 organizations had 'really damaging' intrusions.