logo

N-able N-central Flaw Exploited in the Wild as CISA Adds Three to KEV Catalog

ID: 170b7561-290f-579f-8e36-1fee27d39c35

STIX ID: report--170b7561-290f-579f-8e36-1fee27d39c35

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Do Son

...
...

CISA added three actively exploited CVEs to its KEV list: a critical N-able N-central authentication bypass used in real intrusions against MSPs, a critical IBM Langflow unauthenticated code-injection (CVE-2026-9198), and an Apache Tomcat encryption weakness (CVE-2026-34486). Patches/hotfixes are available (apply N-central hotfix and Tomcat updates 11.0.21/10.1.54/9.0.117); defenders should hunt for rogue accounts (e.g., a “veeam” account), unexpected RMM installs, and IOCs such as an svchost.exe in a user Documents folder.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.