# AI-Piloted Hackers and a 9.8-Severity RCE: CISA's Latest KEV Additions Signal a Dangerous New Playbook
## The Threat
Three vulnerabilities landed in CISA's Known Exploited Vulnerabilities catalog on August 5, 2026 — a critical remote code execution flaw in Langflow, an encryption bypass in Apache Tomcat, and an authentication bypass in N-able's N-central remote management platform. All three carry evidence of active exploitation, and the circumstances behind at least one of them should change how defenders think about autonomous threat actors.
The Langflow vulnerability, CVE-2026-9198, is as bad as it gets: unauthenticated attackers can achieve full remote code execution on default deployments without any preconditions. Langflow has become a popular platform for building AI agent workflows, which means it sits in a particularly dangerous place in the modern stack — exposed to the internet by design, often running with elevated privileges, and increasingly common in enterprise environments. Security defects in Langflow have been weaponized repeatedly over the past several months, and this round is no different.
The Tomcat flaw, CVE-2026-34486, is more nuanced but no less serious in clustered environments. It bypasses EncryptInterceptor, the component responsible for encrypting traffic between Tomcat cluster nodes. That's not a minor detail — EncryptInterceptor exists to protect pre-shared key material flowing between servers. Strip that encryption and an attacker positioned on internal network segments can read or manipulate inter-node communications. Most concerning is who's behind the exploitation: Unit 42 has attributed it to a Chinese-speaking threat actor who used DeepSeek, running through the Hermes Agent framework, as an autonomous offensive operator — letting AI conduct targeting research, pivot between vulnerabilities, and manage its own compute budget across hundreds of attack attempts.
## Severity and Impact
| CVE | CVSS Score | Vector | Attack Complexity | Authentication Required | CWE |
|-----|-----------|--------|-------------------|------------------------|-----|
| CVE-2026-9198 | 9.8 (Critical) | Network | Low | None | CWE-94 (Code Injection) |
| CVE-2026-34486 | 7.5 (High) | Network | Low | None | CWE-311 (Missing Encryption of Sensitive Data) |
| CVE-2026-18556 | 8.2 (High) | Network | Low | None | CWE-287 (Improper Authentication) |
| CVE-2026-18577 | 8.2 (High) | Network | Low | None | CWE-287 (Improper Authentication) |
Note on the N-central entries: CVE-2026-18556 is the original authentication bypass; CVE-2026-18577 tracks N-able's incomplete first patch attempt. Both are now confirmed exploited, meaning organizations that applied the initial fix may still be exposed.
## Affected Products
Langflow
Apache Tomcat
N-able N-central
Additional targets in the broader campaign (not KEV-listed but confirmed exploited by the same actor):
## Mitigations
Langflow (CVE-2026-9198)
Apache Tomcat (CVE-2026-34486)
N-able N-central (CVE-2026-18556 / CVE-2026-18577)
FCEB agencies must have all fixes applied by August 7, 2026 per CISA's binding operational directive.
## References
---
## HackWire Analysis
The headline vulnerability here is CVE-2026-9198 — a 9.8 RCE with no authentication gate in a platform that's purpose-built for internet-connected AI workflows. But the story that will matter longer is how the Tomcat exploitation happened.
Unit 42's writeup on the knaithe/KnYuan actor describes something the security community has been theorizing about for years: a threat actor using an AI system — in this case DeepSeek running through the Hermes Agent framework — not just to automate known exploits, but to autonomously conduct targeting research, evaluate environments, and pivot when primary attacks fail. When the Langflow exploit hit a hardened target, the AI agent didn't stop — it researched alternatives, found n8n as a secondary vector, and adjusted. The actor is described as deliberately letting the AI narrow scope to conserve compute costs. That's not scripted automation; that's resource-aware offensive decision-making.
The operational implication for defenders is uncomfortable: the economics of targeted reconnaissance just collapsed. What previously required hundreds of hours of manual analysis — evaluating 460 targets, sampling environments, prioritizing by exploitability — now runs in minutes. Defenders who rely on "we're too small" or "we're not interesting enough" as implicit protection should revisit that assumption. The targeting cost for a sophisticated actor with AI-assisted operations approaches zero.
For organizations running any combination of Langflow, n8n, or other AI workflow platforms on internet-accessible infrastructure: this campaign specifically hunted that attack surface. If you built AI pipelines and left the orchestration layer exposed, assume you were scanned. The N-central authentication bypass adds another dimension — RMM platforms with global network access are the crown jewels for any actor looking to pivot at scale, and a broken initial patch is exactly the kind of noise that lets compromises age undetected.
Patch the three KEV entries first. Then audit your AI workflow infrastructure with the same urgency you'd apply to a core authentication system.
— HackWire Editorial
## Related Coverage