CISA Issues Urgent Directive: Patch Actively Exploited Flaws in Langflow, N-central, and Apache Tomcat
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has mandated federal agencies to immediately address three actively exploited vulnerabilities in **IBM Langflow**, **N-able N-central**, and **Apache Tomcat**. These critical and high-severity flaws pose significant risks, with public proof-of-concept exploits and active attack campaigns underscoring the urgency of mitigation.

**CISA** has issued a stark warning, giving federal agencies a mere three days to patch critical vulnerabilities in widely used software. The directive targets **IBM Langflow**, **N-able N-central**, and **Apache Tomcat**, all of which are confirmed to be under active exploitation by threat actors.
### Critical Flaw in IBM Langflow
The most severe of the trio is a vulnerability in **IBM Langflow**, a visual framework for building AI agents, tracked as **CVE-2026-9198**. This flaw carries a critical **CVSS** score of 9.8 out of 10. It enables an unauthenticated attacker to achieve remote code execution (RCE) on default **Langflow** deployments by chaining two API endpoints to bypass authentication and execute arbitrary code.
Publicly available proof-of-concept (PoC) exploits for **CVE-2026-9198** emerged in late July, providing complete instructions for exploitation. This isn't the first time **Langflow** has been in **CISA**'s crosshairs; the agency previously alerted on **CVE-2026-0770**, another critical **Langflow** vulnerability also exploited in attacks to gain RCE with root privileges.
### N-able N-central Authentication Bypass
**N-able**'s remote monitoring and management platform, **N-central**, is also affected by a high-severity vulnerability, **CVE-2026-18576**. This flaw allows attackers to hijack administrative accounts without authentication. While **N-able** initially patched an earlier iteration of this vulnerability, the fix proved insufficient, leading to a new method of exploitation.
On August 1st, **N-able** warned customers of active exploitation targeting this new vulnerability. An emergency hotfix was released shortly after, with the company urging all users to install it, as the flaw impacts all **N-central** versions prior to 2026.3.
### Apache Tomcat Incomplete Fix Exploited
Rounding out the list is a high-severity **Apache Tomcat** vulnerability, **CVE-2026-34486**, with a **CVSS** score of 7.5. This flaw stems from an incomplete fix for **CVE-2026-29146**, a critical vulnerability (CVSS 9.8) related to missing encryption of sensitive data.
Researchers at **Palo Alto Networks Unit 42** reported on July 30 that a Chinese-speaking threat actor attempted to exploit **CVE-2026-34486** in a manual campaign. The objective was to plant reverse shells on nine **Apache Tomcat** servers, highlighting the real-world impact of even seemingly minor security oversights.
### CISA's Call to Action
**CISA** has confirmed that all three vulnerabilities are being actively leveraged in attacks and has added them to its catalog of Known Exploited Vulnerabilities (**KEV**). While the agency did not disclose the specific types of attacks, or if they are linked to ransomware campaigns, the immediate threat is clear.
Federal agencies have until the end of Friday, July 7th, to apply all available mitigations for these targeted products. This directive serves as a critical reminder for all organizations, not just federal entities, to prioritize patching and bolster their defenses against these actively exploited threats.