CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026, after confirming active exploitation in production environments.

CVE-2026-9198 affects Langflow, a low-code AI workflow platform. The flaw carries a CVSS score of 9.8 and permits unauthenticated attackers to inject code and achieve remote code execution. Langflow users operating the platform without proper network segmentation face immediate risk. An attacker needs only network access to the Langflow instance to exploit this vulnerability. No authentication is required.

Apache Tomcat was also flagged, though specific CVE details remain incomplete in available reporting. Tomcat deployments in production environments require immediate patching, as the agency considers the flaw actively exploited.

N-central, the remote monitoring and management platform from N-able, rounds out the trio. This software manages IT infrastructure across thousands of organizations, making exploitation particularly damaging. Compromised N-central instances could grant attackers lateral movement access to customer networks.

CISA's inclusion of these vulnerabilities in the KEV catalog signals federal agencies and critical infrastructure operators must remediate immediately. Threat actors actively exploit these flaws, making patches non-negotiable. Organizations running Langflow should isolate instances behind firewalls or networks that require VPN access. Verify authentication requirements are enforced.

For Tomcat and N-central users, applying vendor patches takes priority. Check N-able's security advisory for N-central patch availability and deployment timelines. Tomcat administrators should consult Apache's security documentation for the specific flaw and apply updates across all affected systems.

Security teams should scan networks for these products in use. Inventory management systems often miss internal tools and legacy deployments. Threat actors exploit forgotten installations regularly.

The high CVSS