CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
CISA added three actively exploited vulnerabilities to its KEV catalog: Langflow RCE (CVE-2026-9198, CVSS 9.8), Apache Tomcat encryption bypass (CVE-2026-34486, CVSS 7.5), and N-able N-central authentication bypass (CVE-2026-18556/CVE-2026-18577, CVSS 8.2) A Chinese-speaking threat actor (aliases knaithe/KnYuan) is leveraging DeepSeek via the Hermes Agent framework to autonomously identify and exploit vulnerabilities across internet-exposed devices The AI agent demonstrated adaptive behavior by
Analysis
TL;DR
- CISA added three actively exploited vulnerabilities to its KEV catalog: Langflow RCE (CVE-2026-9198, CVSS 9.8), Apache Tomcat encryption bypass (CVE-2026-34486, CVSS 7.5), and N-able N-central authentication bypass (CVE-2026-18556/CVE-2026-18577, CVSS 8.2)
- A Chinese-speaking threat actor (aliases knaithe/KnYuan) is leveraging DeepSeek via the Hermes Agent framework to autonomously identify and exploit vulnerabilities across internet-exposed devices
- The AI agent demonstrated adaptive behavior by conducting autonomous research to pivot from failed Langflow exploits to alternative vulnerabilities in n8n when initial breach attempts failed
- The actor targeted over 460 systems using a hybrid approach combining autonomous AI-driven scanning and manual exploitation, completing in minutes what would normally require hundreds of hours of manual analysis
- Federal Civilian Executive Branch agencies were given an urgent deadline of August 7, 2026, to patch against these actively exploited flaws
Why It Matters
This represents a significant escalation in AI-augmented cyber warfare, demonstrating how threat actors are operationalizing large language models like DeepSeek as autonomous offensive operators capable of independent vulnerability research and exploitation chaining. For AI practitioners and security teams, it underscores the dual-use risk of open-source AI platforms like Langflow and the urgent need to treat AI-enabled autonomous attack campaigns as a realistic and growing threat vector.
Technical Details
- CVE-2026-9198 (Langflow RCE, CVSS 9.8): Unauthenticated code injection vulnerability in default Langflow deployments allowing full remote code execution; patched in version 1.10.1 (July 2026). Langflow is an open-source AI application development platform that has seen repeated weaponization of security defects.
- CVE-2026-34486 (Apache Tomcat, CVSS 7.5): Missing encryption of sensitive data vulnerability bypassing EncryptInterceptor, a cluster component that provides pre-shared key encryption for inter-node messages; patched in April 2026 (versions 11.0.21, 10.1.54, 9.0.117).
- CVE-2026-18556 / CVE-2026-18577 (N-able N-central, CVSS 8.2): Authentication bypass vulnerability where an incomplete initial fix prompted N-able to issue a follow-up patch, with both versions now confirmed as actively exploited.
- Hermes Agent + DeepSeek Framework: The threat actor deployed DeepSeek through the Hermes Agent framework as an autonomous offensive operator, enabling the AI to narrow targeting scope to conserve compute resources while executing hundreds of hours of manual analysis in minutes.
- Adaptive Exploitation Behavior: When initial exploitation of CVE-2026-33017 (Langflow, CVSS 9.8) failed due to restrictive target configurations, the AI agent autonomously researched and identified alternative vulnerabilities including flaws in n8n, demonstrating real-time adaptive attack chaining.
- Additional manually exploited vulnerabilities: Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), and IKE VPN (CVE-2026-33824) were also targeted by the same adversary.
Industry Insight
- Organizations deploying open-source AI development platforms like Langflow must treat default configurations as inherently risky; unauthenticated RCE vulnerabilities in AI tooling pose direct pathways to full infrastructure compromise and should be patched with extreme urgency.
- The emergence of AI-driven autonomous hacking campaigns marks a paradigm shift in threat actor capabilities—defensive strategies must evolve to account for adversaries that can perform rapid vulnerability research, adaptive exploitation chaining, and compute-aware targeting at machine speed.
- Patch management cycles must be dramatically accelerated for internet-exposed components, particularly when CISA issues KEV catalog entries with active exploitation evidence; the narrow window between vulnerability disclosure and weaponization (as demonstrated by the Tomcat and Langflow flaws) leaves little room for delayed remediation.
Disclaimer: The above content is generated by AI and is for reference only.