CYBERSECURITYTRACKER
TRACKING6,916 stories in this site build1,447 vulnerability news stories in this site build
Permanent story citation

CISA Adds Three Known Exploited Vulnerabilities to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3846

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-9198 (IBM Langflow code injection), CVE-2026-18556 (N-able N-central authentication bypass), and CVE-2026-34486 (Apache Tomcat missing encryption). Binding Operational Directive 26-04 requires federal agencies to prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices.

Why it matters: Federal agencies must immediately prioritize patching these three vulnerabilities on internet-facing systems; all other organizations should treat KEV Catalog additions as signals for urgent remediation given evidence of active exploitation in the wild.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 4, 2026: CVE-2026-9198 (IBM Langflow code injection), CVE-2026-18556 (N-able N-central authentication bypass), and CVE-2026-34486 (Apache Tomcat missing encryption). Federal agencies must prioritize patching these high-risk vulnerabilities on publicly exposed assets under Binding Operational Directive 26-04, and all organizations are encouraged to adopt similar risk-based remediation practices.

Why it matters: Federal agencies must patch these three vulnerabilities immediately on exposed systems; all other organizations should treat them as high priority since they enable full asset control post-exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 4, 2026: CVE-2026-9198 (IBM Langflow code injection), CVE-2026-18556 (N-able N-central authentication bypass), and CVE-2026-34486 (Apache Tomcat missing encryption). Federal agencies must prioritize patching these high-risk vulnerabilities on publicly exposed assets under Binding Operational Directive 26-04, and all organizations are encouraged to adopt similar risk-based remediation practices.

Why it matters: Federal agencies must patch these three vulnerabilities immediately on exposed systems; all other organizations should treat them as high priority since they enable full asset control post-exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary