CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 4, based on evidence of active exploitation. They are CVE-2026-9198, an IBM Langflow code injection flaw; CVE-2026-18556, an authentication bypass in N-able N-central; and CVE-2026-34486, a missing-encryption issue in Apache Tomcat.
The N-central entry is the latest turn in an attack wave that began late July. N-able disclosed CVE-2026-18577, an authentication bypass with a CVSS score of 8.2 that gives attackers full administrative access to an N-central console, exploited since July 31. Huntress observed attackers pivoting from compromised consoles into managed endpoints and creating Cloudflare-based tunnels for persistent access. CISA gave federal agencies until August 6, just three days, to remediate.
The Langflow and Tomcat entries expand the catalog beyond remote monitoring tools. Langflow is a popular low-code AI workflow builder; code injection there can lead to full server compromise. The Tomcat flaw concerns missing encryption of sensitive data, a frequent precursor to credential theft.
Under Binding Operational Directive 26-04, agencies must prioritize KEV-listed flaws on publicly exposed assets. CISA encourages all organizations to treat the catalog as a patching priority list. Huntress data shows most cloud-hosted N-central instances were patched by August 3, but 28.6 percent of observed self-hosted servers remained vulnerable and internet-exposed. NHS England assessed that further exploitation is likely.
