CISA Adds Three Known Exploited Vulnerabilities to Catalog

Summary

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively being exploited. These vulnerabilities include an IBM Langflow code injection flaw, an N-able N-central authentication bypass, and an Apache Tomcat encryption issue. The update aligns with Binding Operational Directive (BOD) 26-04, which mandates FCEB agencies prioritize remediation of high-risk, exploited vulnerabilities.

IFF Assessment

FOE

The article announces new vulnerabilities that are actively being exploited, posing a direct threat to organizations and requiring urgent attention from defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 07, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, especially federal agencies, must prioritize patching these newly identified exploited vulnerabilities to mitigate active threats. The inclusion in CISA's KEV Catalog signals that these flaws are not just theoretical but are actively being leveraged by malicious actors.

Read Full Story →