Federal agencies are facing a critical deadline to address three actively exploited vulnerabilities, as highlighted by the Cybersecurity and Infrastructure Security Agency (CISA). The agency has added Langflow RCE, a missing encryption flaw in Apache Tomcat, and an authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog. This designation signals that these flaws are being leveraged by threat actors in real-world attacks, necessitating immediate action.
The Langflow Remote Code Execution (RCE) vulnerability is particularly concerning as it allows unauthenticated attackers to gain full control over default deployments through a code injection flaw. KEVIntel data indicates that exploitation attempts have been steadily increasing since late June, demonstrating the active threat landscape surrounding this issue. Organizations utilizing Langflow should prioritize patching and implementing mitigation strategies as soon as possible.
Another vulnerability of significant concern is a missing encryption flaw within Apache Tomcat. This bypass allows attackers to circumvent the EncryptInterceptor component, which normally adds pre-shared key encryption to messages exchanged between nodes in a cluster. This compromises the security and integrity of communication within Tomcat environments; updating to versions 11.0.21, 10.1.54, or 9.0.117 is crucial for affected deployments.
The authentication bypass vulnerability in N-able N-central (CVE-2026-18556) carries a CVSS score of 8.2 and presents another serious risk. While an initial patch was released, it proved incomplete, prompting N-able to issue a subsequent update tracked as CVE-2026-18577. The ongoing exploitation attempts, with over 220 recorded since late June, demonstrate the persistence of this threat and the need for immediate remediation.
CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies implement these necessary fixes by August 7th. The agency’s decision to add these vulnerabilities to the KEV catalog reflects the severity of the threat and underscores the importance of proactive vulnerability management practices. Organizations should prioritize patching systems and monitoring for signs of compromise, given the active exploitation observed in the wild.
Sources:
