CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting the N-able N-central authentication bypass (CVE-2026-18556) as the most severe, with a CVSS score of 8.2. Other vulnerabilities include a critical code injection flaw in IBM Langflow (CVE-2026-9198) rated at 9.8, and a data encryption issue in Apache Tomcat (CVE-2026-34486) rated at 7.5.
Organizations are urged to patch these vulnerabilities by August 7, 2026, to prevent breaches that could impact multiple clients. The content emphasizes the importance of prompt action in response to these identified threats.