CISA has ordered federal agencies to quickly mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat. The flaws include critical remote code execution and account hijacking issues that threat actors are already using in attacks, with proofs of concept and exploitation activity publicly observed. #IBMLangflow #Ncentral #ApacheTomcat #CVE-2026-9198 #CVE-2026-18576 #CVE-2026-34486 #CVE-2026-0770
Keypoints
- CISA gave federal agencies three days to mitigate three actively exploited vulnerabilities.
- IBM Langflowβs CVE-2026-9198 allows unauthenticated remote code execution in default deployments.
- Threat actors publicly released proof-of-concept exploits for CVE-2026-9198.
- N-ableβs N-central flaw CVE-2026-18576 can let attackers hijack administrative accounts without authentication.
- Apache Tomcat CVE-2026-34486 has been used in a manual campaign to plant reverse shells on servers.