INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CISA Warns of Langflow, N-central Apache Tomcat Flaws

| 2026-08-05 15:51 CRITICAL HIGH VULNERABILITY DISCLOSURE ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has identified multiple critical vulnerabilities in various software applications, including IBM Langflow visual framework for building AI agents, N-central remote monitoring and management platform, Apache Tomcat, and others. These flaws have been exploited by threat actors to gain unauthorized access and execute malicious code, with the most severe vulnerability being CVE-2026-9198 in IBM Langflow, rated 9.8 out of 10. The agency has issued alerts for these vulnerabilities and ordered federal agencies to apply available mitigations by July 7th.
Technical Mitigations AI-generated
I can provide you with the following technical mitigations: * Patch DD-WRT to CVE-2021-27137 (CVSS score of 8.1) using a secure update mechanism, such as a signed package from the official DD-WRT repository. * Implement a secure patch for Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 (CVSS score of 9.8), including: + Regularly updating and patching all components to ensure no known vulnerabilities are present. + Implementing a secure update mechanism, such as a signed package from the official Langflow repository or a trusted source. * Apply a security patch for WordPress Core Interpretation Conflict Vulnerability CVE-2026-60137 (CVSS score of 5.9) using a secure update mechanism, such as: + Using a trusted source, like the official WordPress repository, to ensure all updates are verified and validated before installation. + Implementing a secure patching process, including verification of signatures and integrity checks. These mitigations can help protect against known vulnerabilities in Langflow, N-central, Apache Tomcat, DD-WRT, and WordPress. However, please note that these solutions may not be foolproof and should be used as part of a comprehensive security strategy to mitigate potential threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-60137CVE-2026-60137 CVE-2026-18576CVE-2026-18576 CVE-2026-0770CVE-2026-0770 CVE-2026-63030CVE-2026-63030 CVE-2026-9198CVE-2026-9198 CVE-2026-29146CVE-2026-29146 CVE-2021-27137CVE-2021-27137 CVE-2026-34486CVE-2026-34486
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎the end of Friday, July 7th
CISA has ordered federal agencies to apply available mitigations for Langflow, N-central, and Apache Tomcat by the end of Friday, July 7th.
‎July 24, 2026
Threat actors are exploiting Langflow, N-central vulnerabilities.
vulnerability CVE-2026-60137
‎July 30
Threat actors used a known vulnerability in Apache Tomcat to exploit CVE-2026-34486 on nine servers.
vulnerability CVE-2026-34486
organisation Palo Alto Networks Unit
‎August 1st
Hackers were exploiting a newly discovered vulnerability in Langflow, N-central and Apache Tomcat.
vulnerability CVE-2026-18576
‎August 4
The CVE-2026-60137 vulnerability, which affects Langflow and N-central, will not be patched by July 24, 2026.
vulnerability CVE-2026-60137
‎2026/08/05
Threat actors are using vulnerabilities in IBM Langflow, N-central, and Apache Tomcat to launch attacks.
infrastructure 9.8
organisation CVE-2026-9198
organisation PoC
organisation CVSS
organisation Langflow Inclusion of Functionality
organisation Untrusted Control Sphere Vulnerability
infrastructure 6.9
infrastructure 7.0
organisation CVE-2026
infrastructure 2026.3
organisation API
organisation EDR
organisation SQL
infrastructure 7.0.2
organisation WordPress
organisation WordPress Core
organisation WordPress.org
organisation Cybersecurity
Tactical Metrics
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎2026.3
Software Version
Metrics
infrastructure
‎6.9
Software Version
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎7.0.2
Software Version