threat-intel
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Critical
Summary
The U.S. CISA has added three vulnerabilities to its KEV catalog, including a critical code injection flaw in Langflow, a Tomcat encryption bypass, and an authentication bypass in N-able N-central. These flaws are currently being actively exploited by a Chinese-speaking threat actor, leveraging AI tools to identify and target vulnerable systems, with a focus on automating vulnerability discovery and targeting.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
