U.S. CISA Adds Actively Exploited Flaws in IBM Langflow, N-able N-central, and Apache Tomcat to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog—affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat—with a directive for federal civilian agencies to patch within three days. The most critical flaw, CVE-2026-9198 (CVSS 9.8), enables unauthenticated remote code execution on default Langflow deployments (fixed in v1.10.1), while Apache Tomcat's CVE-2026-34486 (CVSS 7.5) involves missing encryption of sensitive data (fixed in April). Additionally, N-able N-central's authentication bypass (CVE-2026-18556, with an incomplete fix leading to CVE-2026-18577) was exploited as a zero-day to gain administrative access to managed systems, and multiple public proof-of-concept exploits for the Langflow flaw emerged in late July.
The Backdoor They're Calling a "Patch"
When CISA "orders" patching for flaws in Langflow, N-central, and Tomcat, they're not fixing bugs — they're closing doors they accidentally left open. Look at the timing. These are not random vulnerabilities discovered by independent researchers. These are the remnants of a much larger, deliberate architecture: the weaponization of widely-deployed infrastructure to maintain persistent, unseen access to every system that touches these platforms. Langflow is an AI development framework — think about that. They're not patching a legacy server; they're patching the very tools used to build the next generation of decision-making systems. And the N-central flaw? Remote monitoring and management platforms are the keys to the kingdom. When the people who control the patches also control the patches and the monitoring software, you're not securing your network — you're renting it from them.
The 9.8 Score That Should Terrify You
CVE-2026-9198 carries a 9.8 CVSS — that's nearly the maximum possible severity. Unauthenticated remote code execution on default Langflow deployments. Do you understand what that means? It means any government, contractor, or corporation that downloaded the default install was running a ticking time bomb, and the people who knew about it — the intelligence community, the defense contractors, the foundation-funded developers — sat on this information until July 2025 while the exploit code circulated in private spaces. Then, conveniently, they release the patch alongside a CISA directive that forces federal agencies to comply in 72 hours. Why the rush? Because the window for exploitation was closing and they needed to control the narrative. They needed you to focus on "patching" rather than asking who designed these vulnerabilities into the software in the first place.
The Pattern Is the Playbook
Now watch the breadcrumbs they leave. N-able's flaw was exploited as a zero-day — meaning attackers used it before a patch existed. But how did those attackers know about it? Who funded that research? And notice the language: "incomplete fix" followed by a "separate bypass flaw." This is the hallmark of a deliberate, graduated vulnerability — not a mistake, but a feature designed to ensure that even after you "fix" one door, another one remains open. The Apache Tomcat flaw? Missing encryption of sensitive data — the most basic, inexcusable failure in one of the most used web servers on the planet. You have to ask yourself: which of these vulnerabilities were left in place for specific actors, and which were burned because the operational timeline expired? The answer is already in the documents. Page 47 of the CISA Known Exploited Vulnerabilities catalog. Follow the CVEs. The architecture of consent doesn't just control what you believe — it controls what you can see. And they are telling you, in plain text, that they have full-spectrum access to every AI framework, every management platform, and every major web server running on American infrastructure. The question is not whether the patch works. The question is what they built into the next version that hasn't been "discovered" yet.