CuraSec

Act active

CISA KEV: Langflow RCE, Tomcat, and N-central Actively Exploited

2026-08-05 13:01 UTC · The Hacker News · read the source ↗ #cisa-kev#rce#langflow
  • Engineer — Act: All three CVEs are CISA KEV-listed with confirmed active exploitation; CVE-2026-9198 in Langflow is a CVSS 9.8 unauthenticated RCE with a public PoC — patch Langflow, Apache Tomcat, and N-central to current vendor-recommended versions immediately, prioritizing any internet-exposed instances.
  • SOC/IR — Act: Active exploitation of Langflow (unauthenticated RCE) and Tomcat creates immediate hunt obligations — sweep logs for exploitation attempts against these services since August 5, check for post-exploitation indicators (new processes, outbound connections) on hosts running any of the three products.
  • Leader — Plan: Three simultaneous KEV additions including a critical AI-workflow tool (Langflow) warrant confirming your team’s KEV remediation SLA is on track and verifying whether N-central (an RMM platform) is in scope — RMM compromise can enable broad lateral movement across managed endpoints.
  • Signals: CVE-2026-9198 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.