On August 4, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three distinct vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. According to CISA Advisories, these additions stem from verified evidence confirming that these specific flaws are currently being leveraged in active cyber campaigns.
The updated catalog entries target software used in both enterprise and infrastructure environments. The specific vulnerabilities added are listed in the following table:
| CVE ID | Software/Vendor | Vulnerability Type |
|---|---|---|
| CVE-2026-9198 | IBM Langflow | Code Injection |
| CVE-2026-18556 | N-able N-central | Authentication Bypass (Alternate Path or Channel) |
| CVE-2026-34486 | Apache Tomcat | Missing Encryption of Sensitive Data |
These entries are classified as high-risk due to their role as frequent attack vectors. Under Binding Operational Directive (BOD) 26-04, entitled "Prioritizing Security Updates Based on Risk," Federal Civilian Executive Branch (FCEB) agencies are mandated to manage these vulnerabilities with urgency. The directive requires these agencies to prioritize the remediation of KEV-listed vulnerabilities, particularly when they involve publicly exposed assets that permit total system control following successful exploitation.
Furthermore, BOD 26-04 outlines protocols for agencies to verify whether potential compromises occurred on a system before a patch was deployed. While these federal mandates are specific to government departments, CISA advocates for the broader adoption of risk-based management strategies by all private and public sector organizations. The agency continues to maintain a nomination process through which external parties can submit evidence of exploited vulnerabilities that meet the criteria of having a confirmed CVE ID and clear mitigation paths.
Why It Matters
The inclusion of these specific CVEs reflects a shifting priority toward supply chain and middleware security. Because IBM Langflow, N-able, and Apache Tomcat serve as foundational components for many enterprise automation and management systems, a compromise can yield unauthorized lateral movement across a corporate network. By mandating that agencies check for prior compromise, CISA is effectively raising the bar from simple reactive patching to proactive forensic auditing. This signals to the broader cybersecurity industry that the era of 'patch and forget' is over, and continuous monitoring of known-exploited attack surfaces is the new baseline for organizational security health.

Reader Discussion & Insights