THE US Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about vulnerabilities being exploited in IBM Langflow OSS, N-able N-central, and Apache Tomcat. The major vulnerabilities are as follows:
1. **IBM Langflow OSS (CVE-2026-9198)**: Rated 9.8, it allows unauthenticated attackers to execute remote code through API chaining. Patches were rolled out on July 17.
2. **N-able N-central (CVE-2026-18556)**: Rated 7.4, this authentication bypass vulnerability enables unauthorized administrative access. An incomplete fix led to further action and a hotfix (CVE-2026-18577).
3. **Apache Tomcat (CVE-2026-34486)**: Rated 7.5, this security issue involves an EncryptInterceptor bypass introduced in March, allowing unauthenticated code execution.
CISA has included all three vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog and urged federal agencies to patch them by August 7.