ON
← Back to feed
Attackers are attacking IBM Langflow and Apache Tomcat servers
Germany🏛️ PoliticsCenter17 days ago

Attackers are attacking IBM Langflow and Apache Tomcat servers

Ein Artikel berichtet über aktuelle Sicherheitsangriffe auf IBM Langflow und Apache-Tomcat-Server. Sicherheitsforscher warnen vor Exploitation von Schwachstellen, wobei CISA und Palo Alto Networks Unit 42 die Bedrohung analysieren. Die Schwachstelle in IBM Langflow (CVE-2026-9198) gilt als kritisch und ermöglicht potenziell die Ausführung von Schadcode durch die Ausführung von Python-Code während der Überprüfung. Die Apache-Tomcat-Schwachstelle (CVE-2026-34486) ermöglicht Angreifern, den Schutzmechanismus EncryptInterceptor zu umgehen und dadurch Kommunikationsdaten zu manipulieren. IBM und Apache-Tomcat haben jeweils Updates bereitgestellt, um die Sicherheitslücken zu beheben.

Attackers have targeted IBM Langflow and Apache Tomcat servers, prompting urgent security updates from both vendors. According to reports from German cybersecurity outlet heise online, administrators of these systems must immediately deploy patched versions to defend against ongoing attacks. The vulnerabilities were identified through coordinated efforts by security researchers and government agencies. The attacks on IBM Langflow and Apache Tomcat came after warnings from U.S. authorities and independent security teams. The Cybersecurity & Infrastructure Security Agency (CISA) issued a notice highlighting potential risks, while Palo Alto Networks' Unit 42 team documented several incidents involving Apache Tomcat. These findings underscore the growing threat landscape targeting widely used software infrastructure. The impact of the attacks remains unclear, though detailed assessments suggest multiple attempts were made against Apache Tomcat servers. Researchers noted nine separate intrusion attempts, indicating a sustained effort by malicious actors. Meanwhile, IBM’s internal warning highlights a critical vulnerability in its Langflow tool, designated CVE-2026-9198. This flaw allows attackers to exploit default configurations and intercept a superuser token, granting them elevated privileges. With these credentials, intruders can access a function designed to analyze Python code. However, this function executes the code during analysis, enabling the execution of malicious payloads. As a result, affected systems face complete compromise. IBM has released version 1.10.1 of Langflow Open Source Software (OSS) with mitigations in place to address the issue. Apache Tomcat's vulnerability, labeled CVE-2026-34486 as high severity, poses a risk in clustered environments. Attackers can bypass the EncryptInterceptor mechanism, which normally ensures secure communication between cluster nodes. By doing so, they can eavesdrop on data traffic or even alter it, compromising confidentiality and integrity. Apache Tomcat developers have confirmed that patches are available for versions 9.0.117, 10.1.54, and 11.0.21, addressing the identified flaws. Administrators are advised to apply these updates promptly to prevent exploitation. Both IBM and Apache Tomcat have taken steps to mitigate the risks, but the situation underscores the importance of timely patch management. The attacks highlight how critical infrastructure components remain vulnerable despite known weaknesses, emphasizing the need for continuous vigilance and proactive security measures.

Go to the primary sources (4)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 8017 days ago
Attackers are attacking IBM Langflow and Apache Tomcat servers

Ein Artikel berichtet über aktuelle Sicherheitsangriffe auf IBM Langflow und Apache-Tomcat-Server. Sicherheitsforscher warnen vor Exploitation von Schwachstellen, wobei CISA und Palo Alto Networks Unit 42 die Bedrohung analysieren. Die Schwachstelle in IBM Langflow (CVE-2026-9198) gilt als kritisch und ermöglicht potenziell die Ausführung von Schadcode durch die Ausführung von Python-Code während der Überprüfung. Die Apache-Tomcat-Schwachstelle (CVE-2026-34486) ermöglicht Angreifern, den Schutzmechanismus EncryptInterceptor zu umgehen und dadurch Kommunikationsdaten zu manipulieren. IBM und Apache-Tomcat haben jeweils Updates bereitgestellt, um die Sicherheitslücken zu beheben.

Bias read (Center): Der Artikel präsentiert Fakten und Warnungen von Sicherheitsbehörden und Forschern ohne klare politische Einordnung oder Bewertung. Es wird keine politische Haltung oder Agenda vermittelt, sondern lediglich technische Details und Sicherheitsbedrohungen. Der Ton bleibt sachlich und informativ, ohne T

Why factuality (85): The article accurately reports that CISA has added three vulnerabilities to the KEV Catalog, including CVE-2026-9198, CVE-2026-18556, and CVE-2026-34488. It references CISA and provides details about the vulnerabilities, aligning with the primary source document. However, it does not mention BOD 26-

Why objectivity (80): The tone remains informative and focuses on the technical aspects of the vulnerabilities. The article presents the information neutrally but includes some technical jargon and specific details about exploit methods, which may slightly skew the reader's understanding toward the severity of the threat

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories