
CISA has placed three newly exploited vulnerabilities into its Known Exploited Vulnerabilities catalogue, warning that attackers are already leveraging flaws in N‑able N‑central, IBM Langflow and Apache Tomcat to compromise systems. The agency issued an alert on 4 August 2026 linking the defects to active intrusion campaigns and set a patch deadline of 7 August 2026. All three issues have vendor patches available, but delays could allow attackers to maintain footholds inside networks.
CVE‑2026‑18556 describes an authentication bypass in N‑able N‑central that scores 8.2 on the CVSS scale and lets remote users log in without valid credentials, as detailed in CISA’s KEV entry for CVE‑2026‑18556. A related flaw tracked as CVE‑2026‑18577 also affects N‑central and was addressed in a hotfix released by the vendor on 2 August 2026, which can be reviewed in the vendor’s mitigation notice here.
CVE‑2026‑9198 covers a code injection flaw in IBM Langflow scored at 9.8, permitting unauthenticated remote code execution on exposed instances, referenced in the KEV listing for CVE‑2026‑9198. CVE‑2026‑34486 concerns missing encryption of sensitive data in Apache Tomcat, rated at 7.5, which could allow attackers to bypass TLS protections and read or modify session information, as noted in the KEV entry for CVE‑2026‑34486. Both flaws have been marked as actively exploited and appear in the latest KEV update.
CISA noted that the vulnerabilities are under active attack, although no specific threat actor group has been linked to the campaigns. Observations from security researchers show attempts to exploit the Langflow flaw against AI‑orchestration platforms and Tomcat issues against public‑facing web servers. The addition to the catalogue follows a spike in exploitation attempts reported over the last few days.
Administrators should immediately apply the patches supplied by N‑able, IBM and the Apache Tomcat team, following the mitigations outlined in the CISA alert. For N‑central, enabling multi‑factor authentication and reviewing privileged account usage can reduce risk while the hotfix is deployed. Tomcat operators ought to verify that the appropriate cipher suites are enabled and that connectors enforce strong encryption, and Langflow admins should restrict the API to trusted networks or disable the interface until patched.
Organisations are encouraged to subscribe to the CISA KEV feed, test updates in a staging environment before rollout, and share any observed indicators of compromise with relevant ISACs. Maintaining an asset inventory and verifying version numbers helps confirm that the fixes have been applied consistently across the estate.