CISA KEV adds IBM Langflow, N-able, Tomcat flaws
CISA added three actively exploited vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog.
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: a code injection flaw in IBM Langflow, an authentication bypass in N-able N-central, and a missing encryption of sensitive data issue in Apache Tomcat. These additions trigger remediation obligations under Binding Operational Directive (BOD) 26-04, which requires Federal Civilian Executive Branch agencies to prioritize patching of KEV-listed vulnerabilities, particularly those enabling full compromise of publicly exposed assets, and to check for prior compromise before patching.
While the directive is binding only on federal agencies, CISA recommends all organizations adopt the same risk-based prioritization for these three CVEs. No specific threat actors, malware, or campaigns are named in the advisory; the notice is procedural, focused on cataloging exploited vulnerabilities and directing remediation timelines rather than detailing the exploitation activity itself.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free