426/69 Thursday, August 6, 2026

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after finding evidence that they have been actively exploited in attacks. The vulnerabilities are CVE-2026-9198 in IBM Langflow, CVE-2026-18556 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. These vulnerabilities could lead to remote code execution, authentication bypass, or bypass of encryption mechanisms in affected systems.
Reports indicate that CVE-2026-9198 is a Critical Code Injection vulnerability in Langflow OSS versions 1.0.0 through 1.10.0. It could allow unauthenticated attackers to chain multiple API functions to execute code on systems using default configurations. The vulnerability was fixed in Langflow version 1.10.1. CVE-2026-18556 in N-able N-central is an authentication bypass vulnerability that could allow attackers to access systems with administrator-level privileges. N-able has released version 2026.3.1.7 to address this vulnerability and related flaws.
CVE-2026-34486 in Apache Tomcat is a flaw caused by an incomplete fix for a previous vulnerability. As a result, the EncryptInterceptor mechanism, which is used to protect communication between nodes in a Tomcat cluster, could be bypassed. The vulnerability affects Tomcat versions 9.0.116, 10.1.53, and 11.0.20. Users should update to versions 9.0.117, 10.1.54, or 11.0.21, respectively. Organizations using any of these three products should promptly install updates, review event logs and administrator accounts, and look for abnormal system access or connection activity, as all three vulnerabilities have been confirmed as actively exploited.
Source: https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/
