INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Langflow RCE Exploited Vulnerability Flawed Software
| 2026-08-05 15:25 CRITICAL HIGH EXPLOITED VULNERABILITY ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a list of critical vulnerabilities to its Known Exploited Vulnerabilities catalog, citing the presence of IBM Langflow Code Injection Vulnerability CVE-2026-9198 with a CVSS score of 9.8, Apache Tomcat Missing Encryption of Sensitive Data Vulnerability CVE-2026-34486 with a CVS score of 7.5 and N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-18556 with a CVS score of 8.2. These vulnerabilities pose significant risks to the nation's infrastructure, particularly in federal agencies that rely on these systems for critical operations. The CISA has ordered affected organizations to fix the flaws by August 7, 2026, or face potential consequences from threat actors based in Zhuhai, China, who have leveraged AI-powered autonomous hacking agents and DeepSeek frameworks to exploit the vulnerabilities.
Technical Mitigations AI-generated
* Implement secure coding practices, such as input validation and sanitization, to prevent code injection vulnerabilities like CVE-2026-9198 in Langflow.
* Regularly update and patch Apache Tomcat versions to ensure that missing encryption of sensitive data (CVE-2026-34486) is addressed, particularly for critical versions like 11.0.20, 10.1.53, and 9.0.116.
* Use secure authentication mechanisms, such as multi-factor authentication or token-based authentication, in N-able N-central to prevent authentication bypass vulnerabilities (CVE-2026-18556).
* Monitor network traffic for signs of exploitation of CVE-2026-9198 and implement security controls, such as intrusion detection systems or firewalls, to detect and respond to potential attacks.
* Conduct regular vulnerability assessments and penetration testing on Langflow deployments to identify and address potential weaknesses before they can be exploited.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33824CVE-2026-33824
CVE-2026-18577CVE-2026-18577
CVE-2026-3055CVE-2026-3055
CVE-2026-39987CVE-2026-39987
CVE-2026-18556CVE-2026-18556
CVE-2026-9198CVE-2026-9198
CVE-2026-34486CVE-2026-34486
CVE-2026-33017CVE-2026-33017
Target & Sectors
CN
governmentgovernment
Incident Timeline
April 2026
The U.S. CISA added the authentication bypass vulnerability CVE-2026-18556 in N-able N-central to its Known Exploited Vulnerabilities catalog, which was fixed with versions 11.0.21 through 9.0.117.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-18556
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
infrastructure
8.2
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
general_metric
8.2 able central Authentication Bypass
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
organisation
KeV
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
infrastructure
11.0.21
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
infrastructure
10.1.54
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
infrastructure
9.0.117
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
July 2026
Threat actors used a known exploited vulnerability in Apache Tomcat to target CVE-2026-34486.
Click on any entity below to view its context and source!
organisation
CVE-2026-34486
(Fixed in July 2026 with version 1.10.1)
CVE-2026-34486
(CVS score: 7.5) -
infrastructure
7.5
(Fixed in July 2026 with version 1.10.1)
CVE-2026-34486
(CVS score: 7.5) -
infrastructure
1.10.1
(Fixed in July 2026 with version 1.10.1)
CVE-2026-34486
(CVS score: 7.5) -
general_metric
7.5 CVE-2026 CVS score
(Fixed in July 2026 with version 1.10.1)
CVE-2026-34486
(CVS score: 7.5) -
August 5, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Langflow, Apache Tomcat, and N-able N-central vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026.
Click on any entity below to view its context and source!
attribution
Known Exploited
Vulnerability / Patch Management
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026,
added
three flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, citing evidence of active exploitation in the wild.
tactic
T1588.006 - Vulnerabilities
Vulnerability / Patch Management
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026,
added
three flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, citing evidence of active exploitation in the wild.
attribution
KEV
Vulnerability / Patch Management
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026,
added
three flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, citing evidence of active exploitation in the wild.
attribution
Vulnerability / Patch Management
Vulnerability / Patch Management
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026,
added
three flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, citing evidence of active exploitation in the wild.
Aug 05, 2026
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central vulnerabilities to its Known Exploited Vulnerabilities catalog.
2026/08/05
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
infrastructure
9.8
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.
infrastructure
8.2
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.
infrastructure
7.5
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.
infrastructure
1.0.0
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.
infrastructure
1.10.0
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.
infrastructure
2026.1
The second issue, tracked as
CVE-2026-18556
, is an authentication bypass flaw in N-able N-central that allows attackers to access affected systems without valid credentials, impacting versions through 2026.1.
infrastructure
11.0.20
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
infrastructure
10.1.53
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
infrastructure
9.0.116
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
organisation
KeV
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
organisation
CVE-2026-3055
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
organisation
Citrix NetScaler
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
organisation
Apache Tomcat
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
organisation
IKE VPN
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
infrastructure
N8N
When initial attempts to exploit a Langflow flaw (CVE-2026-33017, CVSS 9.8) breach failed due to the target environment's restrictive configurations, the AI agent is said to have conducted autonomous research to identify other higher-value vulnerabilities, including flaws in n8n, to find a way in.
organisation
NetScaler
When one attack path failed, the AI independently searched for alternative flaws, while the attackers also carried out manual exploitation of vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo, and IKE VPN systems.
organisation
EncryptInterceptor
A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes.
organisation
Palo Alto Networks Unit
"This actor attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques," Palo Alto Networks Unit 42
said
.
victims
460 targets
"This actor attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques," Palo Alto Networks Unit 42
said
.
August 7, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Langflow, Apache Tomcat, and N-able N-central vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting federal civilian executive branch agencies to apply necessary fixes by August 7, 2026.
Click on any entity below to view its context and source!
attribution
FCEB
"
Federal Civilian Executive Branch (FCEB) agencies have until August 7, 2026, to apply the necessary fixes and safeguard their networks from active threats.
attribution
Federal Civilian Executive Branch
"
Federal Civilian Executive Branch (FCEB) agencies have until August 7, 2026, to apply the necessary fixes and safeguard their networks from active threats.
Tactical Metrics
Metrics
infrastructure
9.8
Software Version
Click for context!
…ed
the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass…
Metrics
infrastructure
8.2
Software Version
…catalog
:
CVE-2026-9198
(CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
CVE-2026-18556
(CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of…
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
Metrics
infrastructure
7.5
Software Version
….2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-34486
(CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as…
(Fixed in July 2026 with version 1.10.1)
CVE-2026-34486
(CVS score: 7.5) -
Metrics
infrastructure
1.0.0
Software Version
…lity
The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote co…
Metrics
infrastructure
1.10.0
Software Version
…The first issue added to the catalog, tracked as
CVE-2026-9198
, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code exe…
Metrics
infrastructure
2026.1
Software Version
The second issue, tracked as
CVE-2026-18556
, is an authentication bypass flaw in N-able N-central that allows attackers to access affected systems without valid credentials, impacting versions through 2026.1.
Metrics
infrastructure
11.0.20
Software Version
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
Metrics
infrastructure
10.1.53
Software Version
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
Metrics
infrastructure
9.0.116
Software Version
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
Metrics
infrastructure
1.10.1
Software Version
(Fixed in July 2026 with version 1.10.1)
CVE-2026-34486
(CVS score: 7.5) -
Metrics
infrastructure
11.0.21
Software Version
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
Metrics
infrastructure
10.1.54
Software Version
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
Metrics
infrastructure
9.0.117
Software Version
(Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central.
Metrics
infrastructure
N8N
Affected Product
…CVE-2026-33017, CVSS 9.8) breach failed due to the target environment's restrictive configurations, the AI agent is said to have conducted autonomous research to identify other higher-value vulnerabilities, including flaws in n8n, to find a way in.
Metrics
victims
460
Targets
"This actor attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques," Palo Alto Networks Unit 42
said
.
Intelligence Sources
Security Affairs
2026-08-05
The Hacker News
2026-08-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-06T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
infrastructure
Software Version
9.8
version
13x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
9x
organisation
Identified Entity
KeV
entity
8x
timeline
Temporal Reference
August 7, 2026
date
8x
vulnerability
Exploited CVE
CVE-2026-9198
cve
2x
vulnerability
CVSS Score
10
score
2x
general metric
Aug
5
aug
Contextual Telemetry
Context Block
11 METRICS
tactic
Cyber Operation Type
Remote Code Execution
tactic
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Able Central Authentication Bypass
8
able central authentication bypass
source region
Origin Country
China
country
general metric
Score
10
score
general metric
Cve-2026 Cvs Score
8
cve-2026 cvs score
general metric
Exploitation
34,486
exploitation
infrastructure
Affected Product
N8N
software
target region
Target Country
China
country
victims
Targets
460
targets
general metric
Palo Alto Networks Unit
42
palo alto networks unit
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.