Breaking: Langflow RCE (CVSS 9.8) and AI-Driven Tomcat Exploitation Added to CISA KEV — 5 August 2026
IBM Langflow RCE (CVSS 9.8) and Apache Tomcat Under Active Exploitation: CISA Adds Three to KEV
Langflow Code Injection: CVE-2026-9198
CISA has added CVE-2026-9198 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog with a three-day remediation deadline of August 7. This is a code injection vulnerability in IBM Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Langflow is an open-source AI application development platform, and this is not the first time it has been targeted. Security defects in Langflow have been repeatedly weaponised over recent months, including for Monero cryptomining deployment and by the EncForge ransomware group.
A public proof-of-concept exploit is available, and a Metasploit module has emerged. The flaw affects Langflow OSS versions 1.0.0 through 1.10.0, exploiting default configurations that expose auto-login and code-validation endpoints. IBM patched the vulnerability in version 1.10.1, released in July 2026. The combination of unauthenticated RCE, default-config exploitation, and available weaponised exploit code makes this immediately dangerous for any internet-facing Langflow instance.
If you run Langflow in any environment, assume it is being scanned. Upgrade to 1.10.1 or later immediately. If upgrading is not possible today, take the instance offline or restrict network access to trusted sources only. There is no credible workaround beyond patching.
Apache Tomcat Encryption Bypass: CVE-2026-34486
CISA also added CVE-2026-34486 (CVSS 7.5) to the KEV catalog, a missing encryption of sensitive data vulnerability in Apache Tomcat that allows bypass of the EncryptInterceptor cluster component. This vulnerability has been attributed to a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan, who leveraged DeepSeek via the Hermes Agent framework as an autonomous offensive operator.
Palo Alto Networks Unit 42 reported that this actor attempted to exploit over 460 targets, blending autonomous and manual techniques. When initial exploitation attempts against a Langflow flaw failed, the AI agent conducted autonomous research to identify alternative higher-value vulnerabilities, including flaws in n8n, to find a way in. The actor also manually exploited Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), and IKE VPN (CVE-2026-33824) endpoints. The autonomous process executed hundreds of hours of manual targeting analysis in minutes while managing its own compute resources.
This is one of the first documented cases of an AI-driven autonomous hacking campaign with confirmed exploitation attributed to a nation-state aligned actor. The targeting scope included European and global infrastructure. Patched versions are Apache Tomcat 11.0.21, 10.1.54, and 9.0.117.
N-able N-central: Escalation
CISA has now added CVE-2026-18556 to the KEV catalog alongside the previously tracked CVE-2026-18577. Both authentication bypass vulnerabilities in N-able N-central are under active exploitation. The BOD 26-04 deadline for federal agencies is August 6. As of August 3, approximately 28.6% of self-hosted N-central servers remained unpatched. NHS England has assessed that further exploitation is likely. Belgium's Centre for Cybersecurity has issued its own advisory urging immediate action.
This story was covered in yesterday's breaking alert. The key update: if you are running N-central, you must be on build 2026.3.1.7 specifically. Builds 2026.2 and 2026.3 are both insufficient. Check Take Control session logs for unrecognised MSP Support connections, and hunt for Cloudflared services and svchost.exe in user Documents folders on managed endpoints.
So What / Action
Two of the three new KEV entries involve CVSS 9.8 unauthenticated RCE in infrastructure products. The third involves a Chinese AI-driven campaign that autonomously identified and exploited vulnerabilities across 460 targets. Langflow administrators should treat this as an active incident: patch to 1.10.1 immediately or take instances offline. Apache Tomcat administrators should verify they are on 11.0.21, 10.1.54, or 9.0.117 and audit EncryptInterceptor configurations. The knaithe/KnYuan campaign is a signal that autonomous AI-driven exploitation is no longer theoretical. It is operational, and it scales.

