INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CISA Warns of Langflow, N-central Apache Tomcat Flaws
| 2026-08-05 15:51 CRITICAL HIGH VULNERABILITY DISCLOSURE ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has identified multiple critical vulnerabilities in various software applications, including IBM Langflow visual framework for building AI agents, N-central remote monitoring and management platform, Apache Tomcat, and others. These flaws have been exploited by threat actors to gain unauthorized access and execute malicious code, with the most severe vulnerability being CVE-2026-9198 in IBM Langflow, rated 9.8 out of 10. The agency has issued alerts for these vulnerabilities and ordered federal agencies to apply available mitigations by July 7th.
Technical Mitigations AI-generated
I can provide you with the following technical mitigations:
* Patch DD-WRT to CVE-2021-27137 (CVSS score of 8.1) using a secure update mechanism, such as a signed package from the official DD-WRT repository.
* Implement a secure patch for Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 (CVSS score of 9.8), including:
+ Regularly updating and patching all components to ensure no known vulnerabilities are present.
+ Implementing a secure update mechanism, such as a signed package from the official Langflow repository or a trusted source.
* Apply a security patch for WordPress Core Interpretation Conflict Vulnerability CVE-2026-60137 (CVSS score of 5.9) using a secure update mechanism, such as:
+ Using a trusted source, like the official WordPress repository, to ensure all updates are verified and validated before installation.
+ Implementing a secure patching process, including verification of signatures and integrity checks.
These mitigations can help protect against known vulnerabilities in Langflow, N-central, Apache Tomcat, DD-WRT, and WordPress. However, please note that these solutions may not be foolproof and should be used as part of a comprehensive security strategy to mitigate potential threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-60137CVE-2026-60137
CVE-2026-18576CVE-2026-18576
CVE-2026-0770CVE-2026-0770
CVE-2026-63030CVE-2026-63030
CVE-2026-9198CVE-2026-9198
CVE-2026-29146CVE-2026-29146
CVE-2021-27137CVE-2021-27137
CVE-2026-34486CVE-2026-34486
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
the end of Friday, July 7th
CISA has ordered federal agencies to apply available mitigations for Langflow, N-central, and Apache Tomcat by the end of Friday, July 7th.
July 24, 2026
Threat actors are exploiting Langflow, N-central vulnerabilities.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-60137
CISA orders federal agencies to fix these flaws by July 24, 2026, except for
CVE-2026-60137
, which must be fixed by August 4.
July 30
Threat actors used a known vulnerability in Apache Tomcat to exploit CVE-2026-34486 on nine servers.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-34486
On July 30, researchers at
Palo Alto Networks Unit 42 reported
that a Chinese-speaking threat actor tried to exploit the CVE-2026-34486 vulnerability in a manual campaign to plant reverse shells on nine Apache Tomcat servers.
organisation
Palo Alto Networks Unit
On July 30, researchers at
Palo Alto Networks Unit 42 reported
that a Chinese-speaking threat actor tried to exploit the CVE-2026-34486 vulnerability in a manual campaign to plant reverse shells on nine Apache Tomcat servers.
August 1st
Hackers were exploiting a newly discovered vulnerability in Langflow, N-central and Apache Tomcat.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-18576
N-able warned customers on August 1st that hackers were
actively exploiting the new vulnerability
, which received the identifier CVE-2026-18576.
August 4
The CVE-2026-60137 vulnerability, which affects Langflow and N-central, will not be patched by July 24, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-60137
CISA orders federal agencies to fix these flaws by July 24, 2026, except for
CVE-2026-60137
, which must be fixed by August 4.
2026/08/05
Threat actors are using vulnerabilities in IBM Langflow, N-central, and Apache Tomcat to launch attacks.
Click on any entity below to view its context and source!
infrastructure
9.8
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited.
Tracked as CVE-2026-9198, the security issue in IBM’s Langflow visual framework for building AI agents is the most severe, with a critical rating of 9.8 out of 10.
organisation
CVE-2026-9198
In late July, multiple fully functional proof-of-concept (PoC) exploits for CVE-2026-9198 emerged in the public space, with complete instructions on how they can be leveraged.
organisation
PoC
In late July, multiple fully functional proof-of-concept (PoC) exploits for CVE-2026-9198 emerged in the public space, with complete instructions on how they can be leveraged.
organisation
CVSS
Below are the flaws added to the KeV catalog:
CVE-2021-27137
(CVSS score of 8.1) DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2026-0770
(CVSS score of 9.8) Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-63030
(CVSS score of 9.8)
organisation
Langflow Inclusion of Functionality
Below are the flaws added to the KeV catalog:
CVE-2021-27137
(CVSS score of 8.1) DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2026-0770
(CVSS score of 9.8) Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-63030
(CVSS score of 9.8)
organisation
Untrusted Control Sphere Vulnerability
Below are the flaws added to the KeV catalog:
CVE-2021-27137
(CVSS score of 8.1) DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2026-0770
(CVSS score of 9.8) Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-63030
(CVSS score of 9.8)
infrastructure
6.9
The flaws, tracked as
CVE-2026-63030 and CVE-2026-60137
, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
infrastructure
7.0
The flaws, tracked as
CVE-2026-63030 and CVE-2026-60137
, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
organisation
CVE-2026
The flaws, tracked as
CVE-2026-63030 and CVE-2026-60137
, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
infrastructure
2026.3
The company urged customers to install it as the flaw impacted all versions of N-central before 2026.3.
organisation
API
It allows an unauthenticated attacker to execute remotely on default Langflow deployments by chaining two API endpoints to bypass login and run code.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
SQL
CVE-2026-60137
is a high-severity SQL injection flaw in the
author__not_in
parameter of
WP_Query
, affecting.
infrastructure
7.0.2
“The 7.0.2 security release addresses one critical and one high severity security issue.”
organisation
WordPress
Regarding WordPress issues added to the catalog, public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core.
organisation
WordPress Core
Regarding WordPress issues added to the catalog, public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core.
organisation
WordPress.org
Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.”
organisation
Cybersecurity
Cybersecurity researchers at Searchlight Cyber discovered the flaws that can allow remote attackers to compromise vulnerable sites without valid credentials, making immediate patching essential.
Tactical Metrics
Metrics
infrastructure
9.8
Software Version
Click for context!
…rabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited.
Tracked as CVE-2026-9198, the security issue in IBM’s Langflow visual framework for building AI agents is the most severe, with a critical rating of 9.8 out of 10.
Metrics
infrastructure
2026.3
Software Version
The company urged customers to install it as the flaw impacted all versions of N-central before 2026.3.
Metrics
infrastructure
6.9
Software Version
The flaws, tracked as
CVE-2026-63030 and CVE-2026-60137
, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
Metrics
infrastructure
7.0
Software Version
The flaws, tracked as
CVE-2026-63030 and CVE-2026-60137
, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
Metrics
infrastructure
7.0.2
Software Version
“The 7.0.2 security release addresses one critical and one high severity security issue.”
Intelligence Sources
Security Affairs
2026-07-22
BleepingComputer
2026-08-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-06T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
organisation
Identified Entity
PoC
entity
9x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
8x
vulnerability
Exploited CVE
CVE-2026-9198
cve
6x
timeline
Temporal Reference
August 1st
date
5x
infrastructure
Software Version
9.8
version
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
vulnerability
CVSS Score
8
score
2x
general metric
%
54
%
Contextual Telemetry
Context Block
3 METRICS
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Wordpress
7
wordpress
general metric
Websites
500,000,000
websites
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.