CISA adds three exploited Langflow, Tomcat, and N-central flaws to KEV, while Unit 42 links one campaign to a DeepSeek-powered hacking agent.

CVE-2026-18577 is under active exploitation, letting attackers bypass N-able N-central authentication and pivot from servers into managed endpoints.

CISA adds three exploited Langflow, Tomcat, and N-central flaws to KEV, while Unit 42 links one campaign to a DeepSeek-powered hacking agent.