Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update Do Son
    Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
     

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

5 de Agosto de 2026, 12:25

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-9198 (CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
  • CVE-2026-18556 (CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
  • CVE-2026-34486 (CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

The first issue added to the catalog, tracked as CVE-2026-9198, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.

The second issue, tracked as CVE-2026-18556, is an authentication bypass flaw in N-able N-central that allows attackers to access affected systems without valid credentials, impacting versions through 2026.1.

The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.

Researchers linked the exploitation of CVE-2026-34486 to a Chinese-speaking threat actor that used an AI-powered autonomous hacking agent based on DeepSeek to identify and exploit internet-facing vulnerabilities. When one attack path failed, the AI independently searched for alternative flaws, while the attackers also carried out manual exploitation of vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo, and IKE VPN systems.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by August 7, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

❌
❌