Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-29146
CVE
CVE-2026-29146
View on NVD ↗
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
MITRE ATT&CK TTPs
3
T1059
Command and Scripting Interpreter
Execution
T1078
Valid Accounts
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
Source Articles
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of active exploitation of three critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat. The Langflow flaw (CVE-2026-9198) allows unauthenticated remote code execution by chaining API endpoints, with proof-of-concept exploits publicly available. A second Langflow vulnerability (CVE-2026-0770) is also being exploited for root-level remote code execution. The N-central vulnerability (CVE-2026-18576) enables attackers to hijack administrative accounts without authentication, despite prior patching attempts. The Apache Tomcat flaw (CVE-2026-34486), stemming from an incomplete fix for a prior encryption issue, is being exploited by a Chinese-speaking threat actor to deploy reverse shells. CISA has added all three CVEs to its Known Exploited Vulnerabilities catalog and mandated mitigation within three days.
bleeping-computer
Aug 5, 2026