ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
CISA Adds Langflow RCE to KEV as Active Exploitation Evidence Emerges
Source headline: CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Threat level
Critical
Signal strength
85/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog by adding a Langflow remote code injection flaw. The agency reports evidence that the vulnerability is being exploited in the wild. The issue, CVE-2026-9198, affects Langflow instances and can allow unauthenticated attackers to execute code remotely. CISA also added other flaws to KEV, including issues in Tomcat and N-central. Organizations running exposed systems should check for affected versions, apply patches, and review for exploitation indicators.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Open original source