U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
ID: b520bc2a-691d-5048-9ce4-c7354df0cd7a
STIX ID: report--b520bc2a-691d-5048-9ce4-c7354df0cd7a
Feed Name: Security Affairs
CISA added three high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog — CVE-2026-9198 (IBM Langflow code injection leading to unauthenticated RCE), CVE-2026-18556 (N-able N-central authentication bypass), and CVE-2026-34486 (Apache Tomcat missing encryption of sensitive data) — and ordered federal agencies to remediate by August 7, 2026; researchers linked active exploitation of the Tomcat flaw to a Chinese-speaking actor employing an AI-powered autonomous hacking agent and manual follow-up exploits against other network devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
