The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers.
The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.
Three High-Risk Vulnerabilities Added
The latest additions affect widely used enterprise software and infrastructure.
Langflow Remote Code Execution (CVE-2026-9198)
The most critical vulnerability on the list is CVE-2026-9198, a remote code execution (RCE) flaw in Langflow, an open-source platform used to build AI-powered applications.
With a CVSS score of 9.8, the vulnerability allows an unauthenticated attacker to execute arbitrary code on vulnerable Langflow installations that use the default configuration.
The issue was patched in Langflow version 1.10.1, released in July 2026.
Apache Tomcat Encryption Bypass (CVE-2026-34486)
CISA also added CVE-2026-34486, a vulnerability affecting Apache Tomcat.
The flaw weakens protections provided by Tomcat’s EncryptInterceptor, a feature designed to encrypt communications between cluster nodes.
Successful exploitation could allow attackers to bypass message encryption, potentially exposing sensitive communications inside clustered environments.
Apache addressed the issue in:
- Tomcat 11.0.21
- Tomcat 10.1.54
- Tomcat 9.0.117

N-able N-central Authentication Bypass (CVE-2026-18556)
The third vulnerability affects N-able N-central, a popular remote monitoring and management (RMM) platform.
Tracked as CVE-2026-18556, the flaw enables authentication bypass under certain conditions.
Researchers later discovered that the original security update did not completely resolve the issue, prompting N-able to release another patch identified as CVE-2026-18577.
Both vulnerabilities are now listed in CISA’s KEV catalog, indicating that attackers are actively exploiting each of them.
Langflow Continues to Attract Attackers
Although CISA has confirmed active exploitation of the Langflow vulnerability, researchers have not yet disclosed technical details explaining how attackers are using the flaw.
However, Langflow has become an increasingly popular target in recent months as cybercriminals and advanced threat groups focus more attention on AI development platforms.
Its growing adoption within enterprise environments makes it an attractive entry point for attackers seeking access to corporate networks.
Chinese Threat Actor Linked to Tomcat Exploitation
Security researchers have connected exploitation of the Apache Tomcat vulnerability to a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.
According to investigators, the group combines traditional hacking techniques with artificial intelligence to automate parts of its intrusion process.
Researchers believe the attackers used DeepSeek through the Hermes Agent framework to identify vulnerable internet-facing systems and select the most promising attack targets.

AI-Assisted Hacking Accelerates Reconnaissance
The investigation revealed that the threat actor allowed its AI-powered tools to perform reconnaissance, identify exposed systems, and prioritize targets before launching attacks.
When an earlier attempt to exploit another Langflow vulnerability failed due to security controls, the AI reportedly searched for alternative weaknesses, including vulnerabilities in n8n and other publicly exposed applications.
Researchers say this dramatically reduced the time normally required for manual target analysis, allowing hundreds of hours of reconnaissance work to be completed within minutes.
Manual Attacks Continue Alongside AI Automation
Despite using AI to assist with reconnaissance, the attackers also carried out traditional manual exploitation against multiple technologies.
Researchers observed attacks targeting vulnerabilities in:
- Citrix NetScaler
- Apache Tomcat
- Marimo
- IKE VPN services
The combination of automated intelligence gathering and manual exploitation allowed the attackers to pursue a large number of potential victims simultaneously.
Global Campaign Reached More Than 100 Countries
Separate research uncovered another campaign exploiting the Apache Tomcat vulnerability against government agencies and commercial organizations across more than 100 countries.
Investigators discovered an exposed staging server containing reconnaissance data, multiple exploit chains, malware payloads, tunneling utilities, and a cracked version of Cobalt Strike known as GoCobaltStrike.
The infrastructure also included the SNOWLIGHT malware loader, which researchers say was used to establish persistent access on compromised Linux systems.

Broad Attack Infrastructure
Analysis of the attack infrastructure revealed that the operators combined publicly available proof-of-concept exploits with customized malware and commercial offensive tools.
Researchers identified attacks exploiting nine separate vulnerabilities, leading to compromises that included:
- Root-level access on cPanel and WHM servers
- Domain Administrator compromises through ProxyShell
- Large-scale attacks against internet-facing enterprise infrastructure
The campaign demonstrates how threat actors continue to automate vulnerability scanning while rapidly exploiting newly disclosed security flaws.

CISA Urges Immediate Patching
Because all three vulnerabilities are now confirmed to be under active exploitation, CISA is urging organizations to apply available security updates without delay.
Federal Civilian Executive Branch (FCEB) agencies have been instructed to remediate the vulnerabilities by August 7, 2026, in accordance with Binding Operational Directive (BOD) 22-01.
Private-sector organizations are also encouraged to prioritize these updates, review exposed systems, and monitor for signs of compromise.
The latest KEV additions reinforce the growing importance of rapid patch management, especially as threat actors increasingly combine automation, artificial intelligence, and publicly available exploit tools to accelerate cyberattacks.

