CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
What happened
CISA has added CVE-2026-9198 (Langflow), along with Tomcat and N-central vulnerabilities, to its Known Exploited Vulnerabilities catalog. The Langflow flaw is a critical code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution.
Why it ranks #1
Confirmed active exploitation of multiple enterprise technologies listed in CISA's KEV takes top priority over all other categories.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply patches for Langflow, Tomcat, and N-central immediately as per CISA directives.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed