CISA Adds Langflow RCE, Apache Tomcat, and N-able N-central Flaws to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, adding three critical flaws that are actively being exploited in the wild. These include a code injection vulnerability in Langflow (CVE-2026-9198) allowing unauthenticated remote code execution, an authentication bypass in N-able N-central (CVE-2026-18556 and CVE-2026-18577), and a missing encryption of sensitive data vulnerability in Apache Tomcat (CVE-2026-34486). Federal Civilian Executive Branch agencies are mandated to apply necessary fixes by August 7, 2026.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai