CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog after warning they are being actively exploited: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-34486 in Apache Tomcat, and CVE-2026-18556 in N-able N-central. The Langflow issue is a critical code-injection flaw that can lead to unauthenticated remote code execution on default deployments, while the N-central bug is an authentication bypass vulnerability that N-able said was exploited as a zero-day. CISA also noted exploitation of CVE-2026-18577, a separate N-central flaw tied to an incomplete fix for the original issue.
The Apache Tomcat vulnerability allows attackers to bypass EncryptInterceptor protections for cluster-node messages, potentially exposing cluster members to unauthenticated remote code execution. Reporting linked exploitation of the Tomcat flaw to a Chinese-speaking threat actor tracked as knaithe or KnYuan, with activity involving Snowlight malware and AI-enabled autonomous hacking using DeepSeek through the Hermes Agent framework. Under BOD 26-04, Federal Civilian Executive Branch agencies were ordered to remediate the KEV-listed flaws by August 7, and vendors have issued patches including Langflow version 1.10.1 and N-able updates for affected N-central deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On August 5, 2026, CISA added CVE-2026-34486 in Apache Tomcat and CVE-2026-18556 in N-able N-central to the KEV catalog, citing evidence of active exploitation in the wild. The update also indicated that CVE-2026-18577 was being exploited.
SecurityWeek reported that CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog on August 4, 2026, citing active exploitation. The flaw affects IBM Langflow OSS and enables unauthenticated remote code execution on default deployments.
IBM disclosed CVE-2026-9198 on July 17, 2026 and patched it in Langflow OSS version 1.10.1. IBM warned that default deployments were affected and that the bug could be chained for unauthenticated remote code execution.
N-able rolled out a hotfix at the end of July 2026 as exploitation of CVE-2026-18556 intensified. The company said attackers had used the authentication bypass as a zero-day to gain administrative access and reach systems managed through N-central.
Apache Tomcat fixed CVE-2026-34486 in April 2026, including releases 11.0.21, 10.1.54, and 9.0.117. The flaw allowed bypass of EncryptInterceptor protections for cluster-node messages.
SecurityWeek reported that CVE-2026-34486 was introduced in March 2026 by the patch for CVE-2026-29146, changing EncryptInterceptor behavior from fail-closed to fail-open.
After determining the initial fix for CVE-2026-18556 was incomplete, N-able assigned CVE-2026-18577 to the bypass issue and issued a fresh patch. Reporting said threat actors were able to bypass the original remediation.
Proof-of-concept exploit code for CVE-2026-9198 was published roughly one week after IBM's public disclosure. The exploit demonstrated abuse of exposed Langflow endpoints to achieve remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.