Overview
- CISA placed critical vulnerabilities in IBM Langflow, N‑able N‑central, Apache Tomcat, and JetBrains TeamCity on its Known Exploited Vulnerabilities catalog and set binding federal deadlines for fixes.
- The agency required federal civilian agencies to install available patches or mitigations by August 7 for Langflow, N‑central, and Tomcat and by August 8 for TeamCity.
- Public proof‑of‑concept exploits for the Langflow RCE appeared days after vendor patches, N‑able’s initial fix was bypassed and replaced with an emergency hotfix, and CISA says TeamCity is being actively exploited despite JetBrains not seeing attacks at disclosure.
- Researchers linked Tomcat exploitation to a Chinese‑language actor that used AI‑enabled autonomous tooling (DeepSeek/Hermes) to probe and pivot among internet‑exposed targets, showing attackers mix automated and manual techniques.
- Security experts urge immediate patching, network restrictions for internet‑exposed management and CI/CD systems, and hunts for indicators such as web shells or unauthorized admin accounts to limit system takeover and supply‑chain impact.