CISA Adds Langflow, Tomcat, N-central Flaws to KEV Catalog
TL;DR
- CISA added CVE-2026-9198 (Langflow, CVSS 9.8), CVE-2026-34486 (Apache Tomcat, CVSS 7.5), and CVE-2026-18556 (N-able N-central, CVSS 8.2) to its KEV catalog.
- Federal Civilian Executive Branch agencies have until August 7, 2026 to apply fixes across all three products.
- Unit 42 attributes the Tomcat exploitation to a Chinese-speaking actor 'knaithe/KnYuan' running DeepSeek via the Hermes Agent framework against over 460 targets.
The three CVEs CISA moved into its Known Exploited Vulnerabilities catalog this week are, taken on their own, a fairly ordinary Tuesday for federal patch teams. An unauthenticated remote code execution bug in Langflow rated CVSS 9.8, an EncryptInterceptor bypass in Apache Tomcat cluster communications, and an authentication bypass in N-able's N-central whose first fix was itself defeated and had to be re-patched. Federal Civilian Executive Branch agencies have until August 7, 2026 to apply fixes across all three, according to The Hacker News.
The part worth pulling out is who has been exploiting the Tomcat flaw. CVE-2026-34486 has been attributed to an AI-enabled autonomous hacking campaign run by a Chinese-speaking actor operating under the aliases knaithe and KnYuan. According to Palo Alto Networks Unit 42, the actor uses DeepSeek as the reasoning engine behind the open-source Hermes Agent framework, which can drive an operating system terminal, run commands, and reach out to the internet. Unit 42 says this actor 'attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques.'
The same Tomcat CVE has also been weaponized in a separate China-nexus operation targeting government and commercial infrastructure across more than 100 countries to deliver SNOWLIGHT. Langflow's CVE-2026-9198, patched in July 2026 with version 1.10.1, is flagged only as having been repeatedly weaponized in recent months, which is vaguer but enough for CISA to escalate.
The honest caveat is that the reporting doesn't say how many of those 460 targets were actually compromised versus merely probed, whether the DeepSeek-driven workflow was faster or cheaper than a human-run equivalent, or whether the knaithe/KnYuan crew and the SNOWLIGHT campaign are the same operators or distinct opportunists sharing an exploit. What is clear enough to act on is that a Tomcat cluster component patched in April is being scanned at scale in August, and at least one of the campaigns is running with an LLM in the loop rather than a person.
If you operate any of the three products, the August 7 federal deadline is the pragmatic marker to patch or isolate against. For everyone else, the more useful takeaway is the shape of the threat side: exposed-server attack surface is now being worked by agents that don't take breaks, and the interval between patch release and mass exploitation is likely to keep compressing.
Originally reported by thehackernews.com
Read the original article →Original headline: CISA Adds Langflow RCE Flaw to KEV Catalog After Chinese-Speaking Actor Weaponized It via DeepSeek Agent