Threat Intelligence

US Cyber Agency Warns of Active Attacks on Langflow, Tomcat, and N-central Software

The Hacker News · 5 Aug 2026
Key Takeaway If your business uses Langflow, Apache Tomcat, or N-central software, check with your IT provider immediately to confirm patches have been applied, as these flaws are actively being exploited.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog after confirming they are being actively exploited by attackers. The most severe is CVE-2026-9198, a critical code injection vulnerability in Langflow with a near-maximum severity score of 9.8. This flaw allows attackers with no login credentials to gain full remote control over affected systems, making it especially dangerous.

The other two vulnerabilities affect Apache Tomcat and N-central, both widely used in business IT environments—Tomcat as a web application server and N-central as a remote monitoring and management tool often used by IT service providers. Because these tools are common building blocks in many business systems, unpatched versions can give attackers a foothold into networks that may otherwise appear secure.

While this alert originates from a US government agency, Australian businesses using any of these products—directly or through a managed IT provider—should treat it as a priority. Attackers frequently target software worldwide once a vulnerability is publicly known, regardless of geography. Organisations should check with their IT teams or vendors to confirm whether these systems are in use and whether patches have been applied.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.