securityaffairs.com 8/5/2026, 4:29:15 PM · external

CISA Flags Critical Flaws in IBM Langflow, N able and Tomcat

CISA Flags Critical Flaws in IBM Langflow, N able and Tomcat
CyberSIXT Evidence Panel

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included three vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog:

1. **CVE-2026-9198** - A critical code injection vulnerability in IBM Langflow that allows unauthenticated attackers to gain superuser access and execute arbitrary code (CVSS score: 9.8).

2. **CVE-2026-18556** - An authentication bypass flaw in N-able N-central, enabling access without valid credentials (CVSS score: 8.2).

3. **CVE-2026-34486** - A vulnerability in Apache Tomcat that can expose sensitive data due to missing encryption (CVSS score: 7.5). CISA has mandated that federal agencies address these vulnerabilities by August 7, 2026, to protect against potential exploits, with further recommended actions for private organizations to review and mitigate these risks.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline