# Federal Agencies Get 72 Hours to Patch Exploited Flaws in Langflow, N-central, and Apache Tomcat
## The Threat
Three separate software vulnerabilities — spanning an AI development framework, an enterprise remote monitoring platform, and the world's most widely deployed Java web server — are being actively weaponized against real targets. CISA's addition of all three to its Known Exploited Vulnerabilities catalog, with a patch deadline of Friday, August 8, underscores that these aren't theoretical risks: defenders are already behind.
The most alarming of the three hits IBM's Langflow, a visual framework for building AI agent pipelines that has surged in popularity as organizations race to deploy agentic AI applications. CVE-2026-9198 carries a CVSS score of 9.8 and requires no credentials — attackers chain two API endpoints to bypass authentication entirely and drop arbitrary code on the server. Fully functional proof-of-concept exploits have been circulating publicly since late July, and this isn't Langflow's first rodeo: CISA issued a separate emergency alert two weeks ago for CVE-2026-0770, another critical Langflow RCE that grants root-level access. Two critical RCEs in the same framework within a fortnight is a pattern that should prompt any AI team to audit their deployment surface immediately.
N-able's N-central platform adds a particularly uncomfortable dimension: the original patch for CVE-2026-18576 was insufficient, and threat actors found the gap before most customers had even applied the first fix. N-able detected active exploitation and pushed an emergency hotfix on Sunday, August 3rd. For managed service providers running N-central — a platform that by design has elevated access across client environments — an unauthenticated admin account takeover is a breach multiplier. One compromised instance can cascade into dozens of client networks.
## Severity and Impact
| CVE | Product | CVSS Score | Severity | Attack Vector | Complexity | Auth Required | CWE |
|-----|---------|-----------|----------|---------------|-----------|---------------|-----|
| CVE-2026-9198 | IBM Langflow | 9.8 | Critical | Network | Low | None | CWE-306 (Missing Auth for Critical Function) |
| CVE-2026-18576 | N-able N-central | High | High | Network | Low | None | CWE-287 (Improper Authentication) |
| CVE-2026-34486 | Apache Tomcat | 7.5 | High | Network | Low | None | CWE-311 (Missing Encryption of Sensitive Data) |
Note: CVE-2026-34486 is an incomplete remediation of CVE-2026-29146 (CVSS 9.8), meaning organizations that patched the original flaw may still be exposed.
## Affected Products
IBM Langflow
N-able N-central
Apache Tomcat
## Mitigations
Langflow (CVE-2026-9198 and CVE-2026-0770)
N-able N-central (CVE-2026-18576)
Apache Tomcat (CVE-2026-34486)
CISA deadline for federal agencies: All mitigations must be applied by end of day Friday, August 8, 2026.
## References
---
## HackWire Analysis
What makes this trio of KEV additions particularly revealing isn't any one vulnerability — it's the pattern. All three share a common characteristic: the exploitation window opened because someone moved too slowly or incompletely.
N-central's situation is the most troubling. N-able's first patch didn't hold. Attackers found the gap, found a new path, and CISA had to issue an emergency deadline for a vulnerability that theoretically should have been closed weeks ago. This is the "patch bypass" problem security teams rarely talk about openly: fixing a vulnerability in complex enterprise software is genuinely hard, and rushing a patch under pressure increases the odds of shipping an incomplete one. For MSPs running N-central, the risk isn't just their own environment — it's every client network they manage. A single compromised N-central console can pivot laterally into hundreds of organizations. Ransomware operators know this, which is why RMM platforms have been high-priority targets since at least 2022.
Langflow's back-to-back critical CVEs tell a different story: AI infrastructure is being built fast and secured slowly. The visual, low-code nature of Langflow makes it approachable for teams who aren't security-native, and those teams are often the ones deploying it on internet-exposed infrastructure without hardening defaults. With public PoCs already available and a second critical flaw still fresh, any Langflow instance accessible from outside a private network should be treated as compromised until proven otherwise.
The Apache Tomcat exploitation by a Chinese-speaking threat actor installing reverse shells is a quieter signal worth watching. Manual, targeted campaigns against Java web infrastructure suggest reconnaissance and persistence — not opportunistic scanning. Organizations running Tomcat in government, defense, or critical infrastructure contexts should treat this as intelligence, not just a patch notification.
— HackWire Editorial
## Related Coverage