SECURITY·중요도 9·2026. 08. 05.·The Hacker News

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

── KO ──────────────────

CISA, Langflow 및 Tomcat의 원격 코드 실행 취약점을 발견하고 이를 경고했습니다.

미국 사이버 보안 및 인프라 보안국(CISA)이 2026년 8월 5일, 언플로우(Langflow)와 톰캣(Tomcat)에서 발견된 세 가지 취약점을 알려진 악용 취약점 목록에 추가했습니다. 이 중 CVE-2026-9198은 코드 주입 취약점으로, 인증되지 않은 공격자가 원격으로 완전한 제어를 가질 수 있게 합니다. 이 취약점은 악성 공격에 악용되고 있어, 사용자들의 주의가 필요합니다.


── EN ──────────────────

CISA warns about discovered RCE vulnerabilities in Langflow and Tomcat, indicating active exploitation.

On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities catalog. Among them, CVE-2026-9198 is a code injection vulnerability in Langflow that allows unauthenticated attackers to gain full remote control. This highlights a significant security risk, urging users to stay vigilant against potential threats.

원문 보기 →목록으로