CISA's list that day
4 August 2026
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in IBM Langflow, N-able N-central and Apache Tomcat. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-9198Code Injection | IBM Langflow | Patch nowForensic triage required by CISA; Metasploit module | 0.29 | ||
| CVE-2026-18556Authentication Bypass Using an Alternate Path or Channel | N-able N-central | Patch nowForensic triage required by CISA | 0.08 | ||
| CVE-2026-34486Missing Encryption of Sensitive Data | Apache Tomcat | Patch soon | 0.07 |