Breaking: CISA Emergency Directive — N-able N-central Auth Bypass + Langflow RCE + AI-Powered Attack Campaign — 5 August 2026
CISA Emergency Directive: N-able N-central Auth Bypass Under Active Exploit
CISA has issued an Emergency Directive requiring all Federal Civilian Executive Branch agencies to patch CVE-2026-18577, a critical authentication bypass in N-able's N-central remote monitoring and management platform, by August 6, 2026. The three-day remediation window, invoked under Binding Operational Directive 26-04, signals the severity of active exploitation already observed in the wild.
The vulnerability is the result of an incomplete fix for CVE-2026-18556, an earlier authentication bypass. Attackers found an alternative exploitation path and began abusing it in late July. A successful attack grants full administrative control of the N-central console, the same access level reserved for NOC and engineering staff. From there, attackers have been observed pivoting into managed endpoints using N-central's built-in Take Control feature and establishing persistent Cloudflare tunnels via the legitimate "cloudflared" utility.
Huntress, which analyzed logs from affected MSP partners, reports that threat actors connected using a default account named "MSP Support" from IP 173.249.252.200, then conducted domain controller reconnaissance, enumerated running processes, and moved laterally through victim environments. Connections were routed through NordVPN and Mullvad VPN exit nodes. Four IPs are associated with the campaign: 173.249.252.200, 87.249.138.34, 37.19.210.32, and 68.235.46.214.
As of August 3, nearly all cloud-hosted N-central instances had been patched, but 28.6% of self-hosted servers remained exposed and internet-accessible. The UK's NHS and Belgium's Centre for Cybersecurity have both issued urgent advisories. The complete fix is in N-central version 2026.3 HF1. Organizations that cannot patch immediately should consider disabling N-central entirely until remediation is possible.
Langflow RCE Added to KEV as AI-Powered Attack Campaign Emerges
CISA simultaneously added CVE-2026-9198 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog, a code injection flaw in Langflow that allows unauthenticated remote code execution on default deployments. The fix shipped in version 1.10.1 last month, but Langflow has been repeatedly weaponized by threat actors since June.
The context makes this more urgent than a routine KEV addition. Palo Alto Networks Unit 42 has documented a Chinese-speaking threat actor, tracked as knaithe/KnYuan and based in Zhuhai, China, conducting an AI-powered autonomous hacking campaign using DeepSeek via the Hermes Agent framework. When initial exploitation attempts against a Langflow flaw (CVE-2026-33017, also CVSS 9.8) failed due to restrictive target configurations, the AI agent autonomously researched and identified alternative higher-value vulnerabilities, including n8n flaws, to find an entry point. The actor attempted over 460 targets, combining autonomous and manual techniques against Citrix NetScaler, Marimo, Apache Tomcat, and IKE VPN endpoints.
Separately, the Apache Tomcat flaw CVE-2026-34486, also added to KEV today, is being exploited by a China-nexus threat actor targeting government and commercial infrastructure across more than 100 countries. SOCRadar discovered the campaign after analyzing an exposed staging server containing reconnaissance lists, nine weaponized CVEs, a cracked Chinese Cobalt Strike variant, and the SNOWLIGHT Linux loader.
So What / Action
Three immediate actions:
1. N-able N-central: If you run it, patch to 2026.3 HF1 now. Hunt for indicators: files named svchost.exe in user Documents folders, registered Cloudflared services, and the four IPs listed above. Check Take Control logs for unusual sessions. If patching is impossible, disable N-central until you can.
2. Langflow: If any instance is internet-facing, treat it as potentially compromised. Upgrade to 1.10.1 or remove from external access. The AI-powered attack dimension means passive exploitation is no longer theoretical: autonomous agents can now adapt in real time when initial exploit attempts fail.
3. Apache Tomcat: Ensure EncryptInterceptor configurations are current. Versions 11.0.21, 10.1.54, and 9.0.117 fix CVE-2026-34486. If you are running Tomcat clustering with inter-node communication, this is not optional.
The convergence of an Emergency Directive, a CVSS 9.8 KEV addition, and confirmed AI-driven autonomous attack campaigns in the same 24-hour window is not coincidence. The barrier to entry for sophisticated exploitation is dropping. RMM platforms remain high-value targets. Patch cycles matter more than they did last quarter.

