CyberSecurity News
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
AI summary
The US Cybersecurity and Infrastructure Security Agency has added three vulnerabilities to its list of known exploited vulnerabilities, indicating they are being actively exploited. One of the vulnerabilities is a code injection flaw in Langflow that allows unauthenticated attackers to achieve full remote control. This Langflow vulnerability has a CVSS score of 9.8, and is identified as CVE-2026-9198. The agency also added vulnerabilities in Tomcat and N-central to the list. These additions were made based on evidence of active exploitation in the wild. The move is intended to inform organizations of the urgent need to address these specific security issues.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

