Web_Logo
Remote Support
Security Alert: New Flaws Exploited in Apache Tomcat, Langflow
Home » Security Alerts  »  Security Alert: New Flaws Exploited in Apache Tomcat, Langflow

Security Alert: New Flaws Exploited in Apache Tomcat, Langflow

Security researchers have confirmed active attacks against two widely used pieces of business software: Apache Tomcat, a platform many web applications and line-of-business systems run on, and Langflow, an AI development tool. Both flaws have been added to the US Cybersecurity and Infrastructure Security Agency's official list of vulnerabilities under active attack.

  • What it is: Attackers, in some cases using AI tools of their own to speed up the process, are breaking into servers running unpatched versions of Apache Tomcat or Langflow.
  • Who is affected: Any business running Apache Tomcat (common behind custom or line-of-business web applications) or Langflow on their own servers or with a hosting provider.
  • The risk: Successful exploitation can hand an attacker full control of the affected server, without needing a username or password.
  • What to do: Apache Tomcat is fixed in versions 11.0.21, 10.1.54 and 9.0.117. Langflow is fixed in version 1.10.1. If you are unsure whether your business runs either platform, ask your IT provider to check.

We recommend confirming with your IT provider that any internet-facing Tomcat or Langflow deployments are patched, and treating this as a priority rather than routine maintenance.

Source: CISA Known Exploited Vulnerabilities Catalog