🔴 Critical | Source: The Hacker News
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalogue, including a critical RCE flaw in Langflow (CVE-2026-9198, CVSS 9.8), alongside flaws in Apache Tomcat and N-central. The Langflow vulnerability allows unauthenticated attackers to execute arbitrary code remotely, posing a severe risk to any organisation running exposed instances. Active exploitation in the wild makes these high-priority patching targets.
Security Architect’s Take: Audit your environment immediately for any exposed Langflow, Apache Tomcat, or N-central instances and apply vendor patches or mitigations without delay — CISA’s KEV listing confirms active exploitation, so standard patch windows are insufficient here. If patching cannot be done immediately, restrict network access to these services and review logs for signs of compromise.
Original advisory: CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited