CISA Adds Langflow RCE, Apache Tomcat, and N-central Flaws to Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These include a code injection flaw in Langflow (CVE-2026-9198), a missing encryption vulnerability in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556). Federal Civilian Executive Branch agencies have until August 7, 2026, to apply necessary fixes.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai