CISA's list that day

4 August 2026

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in IBM Langflow, N-able N-central and Apache Tomcat. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-9198Code InjectionIBM LangflowPatch nowForensic triage required by CISA; Metasploit module0.29
CVE-2026-18556Authentication Bypass Using an Alternate Path or ChannelN-able N-centralPatch nowForensic triage required by CISA0.08
CVE-2026-34486Missing Encryption of Sensitive DataApache TomcatPatch soon0.07

Other changes that day

  1. CVE-2025-26399 SolarWinds Web Help DeskRansomware use: Unknown to Known.