www.securityweek.com 8/5/2026, 10:11:33 AM · external

CISA warns of exploits in IBM Langflow, Nable, and Tomcat flaws

CISA warns of exploits in IBM Langflow, Nable, and Tomcat flaws
Developing story vulnerability 1 article tracked
CISA adds three actively exploited flaws to KEV catalog
CyberSIXT Evidence Panel

THE US Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about vulnerabilities being exploited in IBM Langflow OSS, N-able N-central, and Apache Tomcat. The major vulnerabilities are as follows:

1. **IBM Langflow OSS (CVE-2026-9198)**: Rated 9.8, it allows unauthenticated attackers to execute remote code through API chaining. Patches were rolled out on July 17.

2. **N-able N-central (CVE-2026-18556)**: Rated 7.4, this authentication bypass vulnerability enables unauthorized administrative access. An incomplete fix led to further action and a hotfix (CVE-2026-18577).

3. **Apache Tomcat (CVE-2026-34486)**: Rated 7.5, this security issue involves an EncryptInterceptor bypass introduced in March, allowing unauthenticated code execution.

CISA has included all three vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog and urged federal agencies to patch them by August 7.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline