Security NEXTAugust 5, 2026🇯🇵Translated from Japanese

CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog Affecting Langflow, Apache Tomcat and N-central

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations to remediate them immediately.

The vulnerabilities added on August 4, 2026, are CVE-2026-9198, CVE-2026-34486, and CVE-2026-18556. Federal agencies have until August 7, 2026, to apply mitigations.

CVE-2026-9198 in Langflow

CVE-2026-9198 is a code injection flaw in Langflow, an open-source platform used to build AI applications. Attackers can chain API requests without authentication to obtain tokens and execute arbitrary code on affected systems.

CVE-2026-34486 in Apache Tomcat

CVE-2026-34486 affects Apache Tomcat. Successful exploitation allows attackers to bypass the EncryptInterceptor mechanism responsible for encrypting traffic between cluster nodes, potentially exposing data in transit.

CVE-2026-18556 and CVE-2026-18577 in N-central

CVE-2026-18556 impacts N-able N-central, an IT operations management platform. The flaw permits authentication bypass via alternate channels. An incomplete remediation for this issue led to the discovery of CVE-2026-18577, which was added to the KEV catalog on August 3, 2026.

Security teams are advised to review the official CISA KEV catalog and apply vendor patches without delay.

Related articles

Security NEXTVulnerabilities & Exploits

Critical Remote Code Execution Flaw Patched in Veeam ONE Backup Management Product

Veeam Software disclosed six vulnerabilities in its backup environment operations management product Veeam ONE on July 29, 2026. The most severe issue, tracked as CVE-2026-64633, permits unauthenticated remote code execution on the agent host and received a maximum CVSS v4.0 base score of 10.0, rated Critical. A second flaw, CVE-2026-58075, allows unauthenticated arbitrary file reads that can lead to local privilege escalation and carries a CVSS score of 8.7. The vendor released updated versions addressing all six issues in Veeam ONE 13.1. Security researchers and administrators are urged to apply the patches immediately given the high severity and lack of authentication requirements for the critical vulnerability.

BoletimSecVulnerabilities & Exploits

Web Application Vulnerabilities Surge as Rapid Development Outpaces Security Reviews

The number of vulnerabilities in web applications continues to rise each quarter with no signs of slowing. Frequent releases, lean teams, and pressure for speed are pushing systems into production with flaws that should have been caught earlier. Vibe Coding is accelerating the problem by enabling anyone to launch applications in days and push dozens of updates daily without integrating cybersecurity into the process. Most new software reaches production without any security review, and attackers are already exploiting the common weaknesses these applications share. Companies face data leaks, service disruptions, and customer exposure from issues that a single test could have identified. The recommended response is AI-driven pentesting that simulates real attacker behavior instead of relying on known patterns. Launching web applications without security testing is becoming an increasingly expensive decision as incident costs far exceed preventive measures.

BoletimSecVulnerabilities & Exploits

Critical Stack Buffer Overflow in TP-Link TL-WR940N Enables Remote Code Execution

A high-severity vulnerability tracked as CVE-2026-12935 with a CVSS score of 8.7 affects the TP-Link TL-WR940N router on hardware version V6. The flaw resides in the RTSP connection tracking module responsible for managing audio and video streaming sessions over the network. It is caused by a stack-based buffer overflow that allows oversized data to corrupt kernel memory, potentially leading to device crashes or full remote code execution. No administrative credentials are required for exploitation, though the attack depends on an RTSP connection initiated by a device already present on the local network. Successful compromise grants attackers the ability to alter router settings, modify DNS servers, intercept traffic, redirect users to malicious sites, and pivot to other connected devices. Users are advised to verify the hardware revision on the device label and apply the region-specific firmware update released by TP-Link.

Security NEXTVulnerabilities & Exploits

N-able Releases Hotfix for Exploited N-central Authentication Bypass Flaw CVE-2026-18577

N-able has published a hotfix addressing a high-severity authentication bypass vulnerability in its N-central IT operations management platform. The flaw, tracked as CVE-2026-18577, allows attackers to bypass authentication through alternative paths or channels and potentially take over user accounts. It affects N-central 2026.1 and earlier versions and stems from an incomplete fix for the earlier CVE-2026-18556 issue. The vulnerability carries a CVSS v4.0 base score of 8.2 and is rated High severity. Exploitation has already been observed in the wild, with Indicators of Compromise including related IP addresses now publicly available. N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) on August 2, 2026, and urges customers to apply the update while also recommending agent updates where possible.