importantSYS.SOURCE: The Hacker News• 2026-08-05T13:10:39+05:30
CISA Identifies Actively Exploited RCE and Authentication Bypass Vulnerabilities in Langflow, Apache Tomcat, and N-central
CISA added three actively exploited vulnerabilities to its KEV catalog, including a critical RCE flaw in Langflow (CVE-2026-9198) and an authentication bypass in N-central. A Chinese-speaking threat actor leveraged AI tools like DeepSeek to exploit these flaws in coordinated campaigns targeting global infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The list of vulnerabilities is as follows -
CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote
*** END OF TRANSMISSION ***