By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Flags Langflow, Tomcat, N-central Flaws as Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026, based on confirmed evidence of their active exploitation in real-world cyberattacks. This inclusion mandates federal agencies to patch these vulnerabilities by a specific deadline to mitigate risks. The first vulnerability, identified as CVE-2026-9198, affects Langflow, an open-source tool used for building and visualizing machine learning applications. This flaw is a critical code injection vulnerability with a high CVSS score of 9.8, indicating severe risk. It allows unauthenticated attackers to execute arbitrary code remotely on affected systems, granting them full control without needing any prior access or credentials. The second vulnerability, CVE-2026-3426, impacts Apache Tomcat, a widely used open-source Java Servlet container. This flaw is a critical remote code execution (RCE) vulnerability that could allow an attacker to execute malicious code on the server. Apache Tomcat is a foundational component for many web applications and services, making this vulnerability a significant concern for organizations relying on it. The third vulnerability, CVE-2026-4734, is associated with N-central, a remote monitoring and management (RMM) solution developed by N-able. This specific vulnerability is also a critical remote code execution flaw, enabling attackers to gain unauthorized access and execute commands on managed systems. RMM tools like N-central are often deployed with high levels of privilege to manage endpoints, making vulnerabilities within them particularly dangerous as they can be leveraged to compromise entire networks. The KEV catalog is a crucial resource maintained by CISA to identify and track vulnerabilities that pose a significant and immediate threat to the U.S. federal government. By adding these flaws, CISA signals that they are not theoretical risks but are actively being weaponized by malicious actors. Organizations, particularly those within the federal sector, are required to implement patches and mitigations for these vulnerabilities within a specified timeframe, typically 15 days from the catalog addition, to comply with federal cybersecurity directives. The inclusion of these three vulnerabilities underscores the ongoing threat landscape and the importance of proactive vulnerability management and timely patching to defend against sophisticated cyberattacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.