CISA Flags Multiple Actively Exploited Vulnerabilities, Including AI-Related Flaws and a Linux Kernel Exploit
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. These include a code injection vulnerability in Langflow (CVE-2026-9198) allowing remote code execution, a missing encryption flaw in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556 and CVE-2026-18577). The exploitation of CVE-2026-34486 has been linked to an AI-enabled autonomous hacking campaign. Additionally, a memory corruption flaw in the Linux kernel's Open vSwitch datapath (CVE-2026-64531), codenamed OVSwrap, allows local users to gain root privileges on many default-configured distributions.
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai