CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

Summary

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating they are being actively exploited. These include a critical remote code execution flaw in Langflow and vulnerabilities in Tomcat and N-central.

IFF Assessment

FOE

The addition of these vulnerabilities to CISA's KEV catalog signifies that they are actively being exploited by threat actors, posing an immediate risk to organizations.

Severity

9.8 Critical

The CVSS score of 9.8 reflects a critical severity, indicating a high likelihood of successful exploitation and significant impact, particularly for the Langflow RCE vulnerability which allows unauthenticated attackers full remote code execution.

CISA KEV: Listed as actively exploited. Federal patch due: August 07, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating these newly added KEV vulnerabilities, especially the critical Langflow RCE flaw. Organizations need to have robust vulnerability management programs in place to quickly identify and address actively exploited threats before they can be leveraged in targeted attacks.

Read Full Story →