Critical

CISA Adds Three Known Exploited Vulnerabilities to Catalog

All CISA Advisories
Actively Exploited

Overview

The Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation. The vulnerabilities include a code injection issue in IBM Langflow (CVE-2026-9198), an authentication bypass in N-able N-central (CVE-2026-18556), and a lack of encryption for sensitive data in Apache Tomcat (CVE-2026-34486). These vulnerabilities are significant threats to federal agencies and other organizations, as they can allow attackers to gain control over affected systems. CISA's Binding Operational Directive 26-04 emphasizes the need for rapid remediation of these high-risk vulnerabilities, urging federal agencies to act promptly. While the directive specifically targets federal agencies, CISA encourages all organizations to prioritize addressing these vulnerabilities to enhance their security posture.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: IBM Langflow, N-able N-central, Apache Tomcat
  • Action Required: Federal agencies are required to rapidly remediate these vulnerabilities, especially on publicly exposed assets.
  • Timeline: Newly disclosed

Original Article Summary

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

Impact

IBM Langflow, N-able N-central, Apache Tomcat

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Federal agencies are required to rapidly remediate these vulnerabilities, especially on publicly exposed assets. Specific patches or updates for the mentioned vulnerabilities are not detailed in the article, but organizations should evaluate their systems for these vulnerabilities and apply necessary updates or mitigations as soon as possible.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Patch, and 2 more.

Related Coverage

When an Agent Fails: Incident Response for AI-Initiated Access Events

SCM feed for Latest

The article discusses the challenges faced by cybersecurity teams when responding to incidents initiated by artificial intelligence. It highlights how AI can create new vulnerabilities, leading to unauthorized access events that traditional security measures might miss. Businesses and organizations are advised to enhance their incident response strategies to account for these AI-driven scenarios, ensuring they can effectively detect and mitigate such threats. The focus is on developing a proactive approach to security that includes monitoring AI activities and implementing robust authentication processes. This is particularly important as AI continues to evolve and become more integrated into various systems.

Aug 23, 2026

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Security Affairs

Iran-linked hackers successfully disabled a power plant in the UK for four days, marking a significant cyberattack on the country's energy sector. This incident is considered the first confirmed attack of its kind in the UK. The timing of the attack coincided with similar incidents targeting water infrastructure across 12 states in the United States, raising concerns about coordinated efforts by these hackers. The impact of such attacks on critical infrastructure is profound, as it not only disrupts services but also poses risks to public safety and national security. As countries increasingly rely on digital systems for essential services, the need for robust cybersecurity measures becomes even more urgent.

Aug 23, 2026

Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

A new version of the malware known as ToxicPanda has been reported, now dubbed ToxicPanda 2.0. This upgraded malware is expanding its reach and has been detected in 16 different countries. Researchers have found that it specifically targets Android car head units, hijacking them for malicious purposes. This poses significant risks for drivers as it can compromise vehicle systems and potentially allow attackers to manipulate navigation and other functions. Users and manufacturers of affected devices need to be vigilant and implement security measures to protect against this evolving threat.

Aug 23, 2026

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Security Affairs

Researchers at Adversa AI have developed a new attack method called Cryptographic Context Injection, which allows attackers to bypass safety controls in AI systems. This technique involves sending encrypted instructions as AES-encrypted payloads that trick the AI into decrypting them within its own execution environment. As a result, attackers can potentially access complete chat histories from Grok, a conversational AI platform. This poses a significant risk to user privacy, as sensitive information could be leaked without any user interaction required. The discovery raises concerns about the security of AI systems and the effectiveness of current safety measures designed to protect user data.

Aug 23, 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News

TikTok has agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice, which accused the company of breaching child privacy laws. The lawsuit claimed that TikTok collected personal information from minors without proper consent, violating federal regulations aimed at protecting children's online privacy. As part of the settlement, TikTok will pay $300 million upfront and an additional $100 million once a previous court order is lifted. This case emphasizes ongoing concerns about how social media platforms handle user data, especially when it comes to minors. The settlement could lead to stricter compliance measures for TikTok and other companies in the industry regarding child privacy protections.

Aug 22, 2026

Named Pipes Under Attack: Securing Windows Interprocess Communication

BleepingComputer

Windows named pipes, a method for fast communication between processes, have been identified as a potential security risk due to weak access controls. This vulnerability allows untrusted processes to potentially access privileged services, posing a threat to system integrity. Security experts from ThreatLocker recommend several strategies to mitigate these risks, including endpoint verification, command authorization, strict input validation, and limiting privileges to what is necessary. These measures can help secure named-pipe communications and protect against unauthorized access. Organizations using Windows systems should take these recommendations seriously to safeguard their environments from potential exploitation.

Aug 22, 2026