CVE-2025-9316Active Exploitation

LOWCVSS 6.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-26: 1Active Exploitation · 2026-05-26: 1Technical Details · 2026-05-26: 105-26
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • WhiskeyHacker@whiskeyhacker
    Active Exploitation

    Langflow is not the only target in this wave. Same campaign: CVE-2025-68613 (n8n RCE), CVE-2025-54068 (Laravel Livewire), CVE-2025-52691 (SmarterMail), CVE-2025-9316 (RMM session ID). 12,000+ systems scanned. Confirmed data theft from an Egyptian aviation organization.

    Post summary

    Multiple CVEs—including n8n RCE and other platform bugs—were exploited in a coordinated campaign that led to data theft from an Egyptian aviation organization, confirming active exploitation.

    11000210
    4.2K followersView on X

Explore more