← Back to Feed
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CVE-2026-9198CVE-2026-18556CVE-2026-34486
August 4, 2026 · CISA (US-CERT) · Severity: HIGH
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. These affect IBM Langflow, N-able N-central, and Apache Tomcat. CISA encourages all organizations to prioritize remediation and adopt risk-based vulnerability management practices.
Key Takeaways
- CISA added three actively exploited vulnerabilities to its KEV Catalog.
- BOD 26-04 requires federal agencies to prioritize remediation of KEV-listed flaws.
- Organizations should review and patch IBM, N-able, and Apache Tomcat vulnerabilities.