# Three Actively Exploited Flaws Hit RMM, AI, and Web Server Infrastructure — CISA Issues Emergency Directive
## The Threat
Three vulnerabilities across fundamentally different parts of enterprise infrastructure are being actively exploited in the wild, and CISA's decision to flag all three simultaneously on August 4 signals a threat environment that isn't slowing down. The affected software spans AI development tooling (IBM's Langflow OSS), managed service provider infrastructure (N-able N-central), and a ubiquitous enterprise web server (Apache Tomcat) — a spread that reflects how opportunistic and diverse exploitation campaigns have become.
The Langflow bug is the most immediately alarming. CVE-2026-9198 is a 9.8-severity remote code execution flaw that requires no authentication, no user interaction, and no special conditions beyond network access. IBM's own disclosure described the attack chain with unusual clarity: one unauthenticated API endpoint handed out superuser bearer tokens to any caller, and a separate code validation endpoint would execute arbitrary Python on demand. An attacker chains the two in seconds. Proof-of-concept code dropped roughly a week after the July 17 disclosure, and real-world exploitation followed shortly after — a gap that's becoming depressingly standard.
The N-able N-central situation is messier and arguably more dangerous in practice. The authentication bypass tracked as CVE-2026-18556 was already being exploited as a zero-day when N-able issued its initial patch. That patch didn't hold — threat actors bypassed it almost immediately, forcing N-able to issue a hotfix and a second CVE (CVE-2026-18577) for the bypass of the bypass. RMM platforms are high-value targets precisely because they offer administrative access to every endpoint under management; a single compromised N-central instance can cascade into a full managed service provider's client base.
## Severity and Impact
| CVE | Product | CVSS Score | Type | Attack Complexity | Authentication Required | CWE |
|---|---|---|---|---|---|---|
| CVE-2026-9198 | IBM Langflow OSS | 9.8 (Critical) | Remote Code Execution | Low | None | CWE-306, CWE-94 |
| CVE-2026-18556 | N-able N-central | 7.4 (High) | Authentication Bypass | Low | None | CWE-287 |
| CVE-2026-18577 | N-able N-central | Not yet scored | Patch Bypass | Low | None | CWE-287 |
| CVE-2026-34486 | Apache Tomcat | 7.5 (High) | EncryptInterceptor Bypass / RCE | Low | None | CWE-295 |
All three vulnerabilities are now listed in CISA's Known Exploited Vulnerabilities catalog. Federal agencies operating under BOD 26-04 face a patch deadline of August 7, 2026.
## Affected Products
IBM Langflow OSS
N-able N-central
Apache Tomcat
## Mitigations
For Langflow OSS:
Upgrade to version 1.10.1 immediately. There is no meaningful workaround — the vulnerable endpoints are part of the default deployment. If upgrading is temporarily blocked, isolate Langflow instances behind strict network controls and revoke any externally reachable access. Given that PoC code is public and exploitation is confirmed, treat any unpatched instance as potentially compromised.
For N-able N-central:
Apply the hotfix N-able released in late July (covering both CVE-2026-18556 and the patch bypass CVE-2026-18577). Review administrative access logs for anomalous sessions, particularly any accounts that gained access during the window between initial patch and hotfix. Audit managed endpoints for signs of lateral movement — N-central's reach into client environments means the blast radius of a successful exploit extends well beyond the RMM server itself.
For Apache Tomcat:
Apply the April 2026 patch if you haven't already. If your environment doesn't use EncryptInterceptor, the risk surface for CVE-2026-34486 is significantly reduced, but upgrade anyway — the underlying padding oracle issue (CVE-2026-29146) and its botched fix represent poor cryptographic hygiene regardless. For clustered deployments, verify that the interceptor chain is configured to fail closed on decryption errors. Consider whether inter-node traffic needs to traverse networks where an attacker could inject messages.
General:
## References
---
## HackWire Analysis
The Tomcat story here deserves more attention than it's getting. CVE-2026-34486 didn't arrive through a researcher finding a new weakness — it was introduced by a developer fixing an existing one. The CVE-2026-29146 patch for a padding oracle bug moved a single line of code and flipped the encryption interceptor from fail-closed to fail-open. That single line turned a fully patched system into one where unauthenticated attackers could push arbitrary data straight into the deserialization layer of every cluster member. StrigaAI's description is clinical but devastating: "The fix moved one line of code."
This is a recurring failure mode in security patching that the industry refuses to address systematically. Patches get rushed, reviewed under time pressure, and often written by engineers who understand the bug being fixed but not the trust model of the surrounding code. The result is a patch that closes the original CVE and opens a new attack surface — and because it ships in what users believe is a hardened version, it often gets less scrutiny than the original vulnerable code did.
The N-able situation compounds this problem. Exploited as a zero-day, patched, bypassed, patched again — this is not a software quality failure, it's a process failure. Zero-day exploitation of RMM software is an ongoing crisis that's barely registering as one. MSPs who rely on N-central for client management need to be asking N-able for a full post-mortem on how both the original bypass and the patch bypass were possible, not just applying hotfixes and moving on.
Meanwhile, the Chinese threat actor campaign combining Snowlight malware and AI-enabled autonomous exploitation of the Tomcat flaw represents a methodological escalation worth watching. Autonomous hacking campaigns using LLM-assisted tooling to chain vulnerabilities at scale aren't theoretical anymore.
— HackWire Editorial
---
## Related Coverage