CybersecurityAugust 5, 2026· via BleepingComputer

CISA flags three critical software flaws under active attack

CISA flags three critical software flaws under active attack

Image : BleepingComputer

Federal agencies have three days to patch three widely used software packages after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central and Apache Tomcat.

The most severe issue is CVE-2026-9198, a code injection flaw in IBM Langflow versions 1.0.0 to 1.10.0 that allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on default deployments. With a CVSS score of 9.8, the flaw gives intruders a direct route to full remote code execution in environments running unpatched Langflow instances. N-able N-central’s CVE-2026-18556 is an authentication bypass tracked at CVSS 8.2, enabling attackers to bypass login mechanisms and assume control of managed systems. Apache Tomcat’s CVE-2026-34486, scoring 7.5, involves missing encryption of sensitive data, exposing credentials and session tokens to interception.

All three flaws were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026, following evidence of exploitation in the wild documented by Security Affairs and The Hacker News.

Immediate patching pressure

Federal civilian agencies must address the flaws within the standard 14-day remediation window, with CISA’s binding operational directive requiring mitigation or removal within three days for cataloged vulnerabilities under active exploitation. Organizations running Langflow, N-central or Tomcat should prioritize vendor-supplied updates and apply compensating controls such as network segmentation and strict access policies until patches are deployed.

Why it matters

These three flaws highlight how quickly attackers weaponize newly disclosed vulnerabilities once they appear on CISA’s KEV list. Langflow’s superuser access path and N-central’s authentication bypass pose outsized risk to managed service providers and large enterprises, while Tomcat’s data exposure undermines secure communications in countless web applications. For defenders, the episode underscores the need for continuous vulnerability scanning, rapid patching cycles, and layered defenses against code execution chains that can pivot from a single exploited service to broader network compromise.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home