CISA Warns of Hackers Exploiting Langflow, N-central, Apache Tomcat Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of hackers exploiting vulnerabilities in IBM Langflow, N-central, and Apache Tomcat. The agency has given federal agencies three days to mitigate the vulnerabilities.
Intelligence analysis by Llama

CISA has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, August 7th. The vulnerabilities allow hackers to execute remote code execution with root privileges.
Imagine you have a super powerful computer that can do lots of things, but someone can hack into it and do bad things without needing a password. That's what's happening with some computers that use Langflow, N-central, and Apache Tomcat. The people in charge of these computers need to fix the problems so hackers can't get in.
Analysis
A Critical Threat to Federal Agencies
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies regarding the exploitation of vulnerabilities in IBM Langflow, N-central, and Apache Tomcat. The agency has given federal agencies three days to mitigate the vulnerabilities, which pose a significant threat to their sensitive data.
The Langflow vulnerability, tracked as CVE-2026-9198, is the most severe, with a critical rating of 9.8 out of 10. It allows an unauthenticated attacker to execute remotely on default Langflow deployments by chaining two API endpoints to bypass login and run code. In late July, multiple fully functional proof-of-concept (PoC) exploits for CVE-2026-9198 emerged in the public space, with complete instructions on how they can be leveraged.
The N-central vulnerability, identified as CVE-2026-18576, allows attackers to hijack administrative accounts without authentication. The flaw received a high-severity rating and has been patched by the vendor. However, the fix was insufficient, and threat actors found a new way to exploit it. N-able warned customers on August 1st that hackers were actively exploiting the new vulnerability.
The Apache Tomcat vulnerability, tracked as CVE-2026-34486, has a high-severity score of 7.5. It stems from an incomplete fix for CVE-2026-29146, a critical vulnerability with a severity rating of 9.8 that is described as the missing encryption of sensitive data. On July 30, researchers at Palo Alto Networks Unit 42 reported that a Chinese-speaking threat actor tried to exploit the CVE-2026-34486 vulnerability in a manual campaign to plant reverse shells on nine Apache Tomcat servers.
CISA has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, August 7th. The agency has not shared what types of attacks are leveraging these vulnerabilities, noting that it is unknown if they are used in ransomware campaigns. However, the agency has added them to its catalog of Known Exploited Vulnerabilities (KEV).
The exploitation of these vulnerabilities poses a significant threat to federal agencies and their sensitive data. It is essential for these agencies to take immediate action to mitigate the risks. The CISA warning serves as a reminder of the importance of regular security updates and patches to prevent such vulnerabilities from being exploited.
Key points
- CISA has warned federal agencies of hackers exploiting vulnerabilities in IBM Langflow, N-central, and Apache Tomcat.
- The agency has given federal agencies three days to mitigate the vulnerabilities.
- The Langflow vulnerability, tracked as CVE-2026-9198, is the most severe, with a critical rating of 9.8 out of 10.
- The N-central vulnerability, identified as CVE-2026-18576, allows attackers to hijack administrative accounts without authentication.
- The Apache Tomcat vulnerability, tracked as CVE-2026-34486, has a high-severity score of 7.5.
If federal agencies take immediate action to mitigate the vulnerabilities, they can prevent hackers from exploiting them and protect their sensitive data. This will also help to prevent potential ransomware campaigns.
If federal agencies fail to take immediate action to mitigate the vulnerabilities, hackers may be able to exploit them and gain access to sensitive data. This could lead to significant consequences, including data breaches and potential ransomware campaigns.



