The Cybersecurity and Infrastructure Security Agency has issued warnings about three vulnerabilities now under active exploitation in the wild. The flaws affect Langflow, N-central, and Apache Tomcat products, with attackers leveraging them to gain unauthorized access and execute malicious code on vulnerable systems.
These vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog, a list that tracks security flaws confirmed to be exploited by threat actors. The catalog serves as a priority remediation guide for federal agencies and private sector organizations seeking to reduce their attack surface against known threats.
The three vulnerabilities enable distinct attack vectors. Attackers can achieve remote code execution, allowing them to run arbitrary commands on compromised systems. Authentication bypass flaws permit unauthorized access without valid credentials. The EncryptInterceptor bypass weakness in Tomcat allows attackers to circumvent encryption protections designed to secure sensitive data.
Organizations running affected versions of Langflow, N-central, or Apache Tomcat face immediate risk from these actively exploited flaws. Federal agencies operating under Binding Operational Directive 22-01 must remediate these vulnerabilities according to CISA's specified timelines. Private sector entities, while not bound by federal directives, face the same threats from exploitation attempts.
Security teams should immediately identify systems running vulnerable versions of these products and apply available patches. Organizations unable to patch immediately should implement compensating controls such as network segmentation, enhanced monitoring for exploitation indicators, and restricting access to affected systems. CISA recommends all organizations treat Known Exploited Vulnerabilities as high-priority remediation targets regardless of sector or regulatory requirements.
Source: https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/


