Act
active
CISA KEV: Langflow RCE, Tomcat, and N-central Actively Exploited
- Engineer — Act: All three CVEs are CISA KEV-listed with confirmed active exploitation; CVE-2026-9198 in Langflow is a CVSS 9.8 unauthenticated RCE with a public PoC — patch Langflow, Apache Tomcat, and N-central to current vendor-recommended versions immediately, prioritizing any internet-exposed instances.
- SOC/IR — Act: Active exploitation of Langflow (unauthenticated RCE) and Tomcat creates immediate hunt obligations — sweep logs for exploitation attempts against these services since August 5, check for post-exploitation indicators (new processes, outbound connections) on hosts running any of the three products.
- Leader — Plan: Three simultaneous KEV additions including a critical AI-workflow tool (Langflow) warrant confirming your team’s KEV remediation SLA is on track and verifying whether N-central (an RMM platform) is in scope — RMM compromise can enable broad lateral movement across managed endpoints.
- Signals: CVE-2026-9198 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.