CISA warned that attackers are actively exploiting CVE-2026-9198 in IBM Langflow OSS, CVE-2026-18556/CVE-2026-18577 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. The three flaws have enabled remote code execution, authentication bypass, and cluster compromise, with exploitation linked to Chinese threat actors and the Snowlight malware family. #IBMLangflowOSS #NableNcentral #ApacheTomcat #CVE20269198 #CVE202618556 #CVE202618577 #CVE202634486 #Snowlight
Keypoints
- CISA said three vulnerabilities are being actively exploited in IBM Langflow OSS, N-able N-central, and Apache Tomcat.
- CVE-2026-9198 in Langflow OSS can lead to remote code execution through chained API abuse.
- CVE-2026-18556 in N-able N-central allowed authentication bypass and administrative access to managed systems.
- CVE-2026-18577 was issued after attackers bypassed the original N-central fix.
- CVE-2026-34486 in Apache Tomcat was exploited in attacks tied to Chinese threat actors and the Snowlight malware family.
Read More: https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/