CISA Adds Three New Vulnerabilities to Known Exploited Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities catalog, citing their potential for exploitation by attackers.
CVE-2026-9198 is a critical vulnerability in IBM Langflow OSS versions 1.0.0-1.10.0 that allows unauthenticated attackers to gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments. The CVSS score for this issue is 9.8.
CVE-2026-18556 is an authentication bypass flaw in N-able N-central that allows attackers to access affected systems without valid credentials, impacting versions through 2026.1. This vulnerability has a CVSS score of 8.2.
The third issue added to the catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data. This vulnerability has a CVSS score of 7.5.
CISA orders federal agencies to fix these flaws by August 7, 2026, citing Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities.