- CISA added three actively exploited vulnerabilities to its KEV catalog on August 5, 2026
- Critical Langflow code injection flaw (CVE-2026-9198, CVSS 9.8) enables unauthenticated remote code execution
- Apache Tomcat encryption bypass linked to AI-driven Chinese-speaking threat actor campaign
- N-able N-central authentication bypass vulnerabilities under active exploitation
- Federal agencies must apply patches by August 7, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026, citing evidence of active exploitation in the wild.
The most severe is CVE-2026-9198, a code injection vulnerability in Langflow with a CVSS score of 9.8 that enables unauthenticated remote code execution on default deployments, according to IBM’s advisory. The flaw was patched in July 2026 with version 1.10.1 of the open-source AI platform.
Meanwhile, CVE-2026-34486 in Apache Tomcat allows attackers to bypass the EncryptInterceptor cluster component, defeating pre-shared key encryption between cluster nodes. Apache patched this vulnerability in April 2026 across versions 11.0.21, 10.1.54, and 9.0.117.
The Tomcat exploitation has been attributed to an AI-enabled autonomous hacking campaign by a Chinese-speaking threat actor using aliases knaithe and KnYuan. The actor leveraged DeepSeek via the Hermes Agent framework to target internet-exposed devices, according to Palo Alto Networks Unit 42.
When initial attempts to exploit a separate Langflow flaw failed due to restrictive target configurations, the AI agent conducted autonomous research to identify higher-value vulnerabilities, including flaws in n8n. “This actor attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques,” Unit 42 researchers said.
Also added to the KEV catalog is CVE-2026-18556, an authentication bypass in N-able N-central with a CVSS score of 8.2. An incomplete fix prompted N-able to issue a fresh patch tracked as CVE-2026-18577, which joined the KEV catalog on Monday, confirming both vulnerabilities are actively exploited.
Federal Civilian Executive Branch agencies have until August 7, 2026, to apply necessary fixes and safeguard their networks.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
