Hackers Weaponize Three Flaws As CISA Sounds Red Alert
By 813 Staff

The first wave of exploitation alerts from CISA this week didn’t land where most security teams were looking. While the industry’s attention was fixed on the usual suspects—identity providers and cloud gateway appliances—the agency’s latest Known Exploited Vulnerabilities catalog quietly added three very different targets: Langflow, SolarWinds N-central, and Apache Tomcat. Internal documents circulating among federal contractors show the additions were made after confirmed intrusions, not merely theoretical proof-of-concepts, which means attackers are already chaining these flaws into live campaigns.
The Langflow entry is the one raising the most eyebrows among practitioners. The low-code AI tooling platform has enjoyed a surge of enterprise adoption, but engineers close to the project say the patched vulnerability—a remote code execution flaw in how the platform handles certain API requests—was flagged internally months ago. The public advisory came later, and the rollout has been anything but smooth. Several organizations running Langflow in production received the CISA alert before their instance vendors even had a stable patch available, leaving a window that threat actors have been actively probing.
SolarWinds N-central, the RMM platform that has already weathered its share of scrutiny, is back in the crosshairs with a separate authentication bypass issue. The agency’s listing suggests the exploit is being used to gain initial access to managed service provider environments, which is the nightmare scenario: a compromise at one MSP can ripple across dozens of downstream small and mid-sized businesses. SolarWinds has pushed a fix, but the company has not confirmed how many customers were exposed before the update was applied.
The Tomcat flaw is less exotic but no less dangerous, given the sheer install base of the open-source server. CISA’s notification does not specify which version line is affected, but sources tracking the exploit say it is being used to drop web shells on internet-facing instances that have not been configured with the latest security manager settings.
The practical takeaway, per @BleepinComputer’s reporting and the agency’s own guidance, is that these are not drill scenarios. Federal civilian agencies have a binding deadline to remediate, and private sector organizations would be wise to treat it as a contract clause, not a suggestion. Expect CISA to follow up with technical details on indicators of compromise in the coming days, but right now, the most urgent step is inventory: knowing which of your assets run these three pieces of software and patching them today.
Source: https://x.com/BleepinComputer/status/2085031025038577749

