CISA Flags Actively Exploited RCE, Tomcat, and N-central Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2026-9198, a code injection vulnerability in Langflow allowing unauthenticated remote code execution; CVE-2026-34486, a missing encryption flaw in Apache Tomcat; and CVE-2026-18556, an authentication bypass vulnerability in N-able N-central.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai