Skip to content
eastbaycyber

CISA Adds 3 Known Exploited Vulnerabilities to Catalog (August 4, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On August 4, 2026, CISA added 3 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-18556, CVE-2026-34486, CVE-2026-9198. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able · N-central

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

Federal due date
2026-08-07
Ransomware use
Unknown
Added
2026-08-04

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache · Tomcat

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Federal due date
2026-08-07
Ransomware use
Unknown
Added
2026-08-04

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Apache KEV history

CVE-2026-9198: IBM Langflow Code Injection Vulnerability

IBM · Langflow

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

Federal due date
2026-08-07
Ransomware use
Unknown
Added
2026-08-04

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

Also added to KEV in August 2026

  • August 31, 2026: CVE-2026-82078, PaperCut NG/MF (PaperCut NG/MF Unsafe Reflection Vulnerability)
  • August 31, 2026: CVE-2026-81578, PaperCut NG/MF (PaperCut NG/MF Missing Authentication for Critical Function Vulnerability)
  • August 27, 2026: CVE-2026-66384, JFrog Artifactory (JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vu)
  • August 27, 2026: CVE-2026-53362, Linux Kernel (Linux Kernel Unspecified Vulnerability)
  • August 27, 2026: CVE-2023-49105, ownCloud ownCloud (ownCloud Improper Authentication Vulnerability)
  • August 26, 2026: CVE-2026-8452, Citrix NetScaler ADC and NetScaler Gateway (Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations wi)
  • August 26, 2026: CVE-2022-0995, Linux Kernel (Linux Kernel Out-of-Bounds Write Vulnerability)
  • August 26, 2026: CVE-2021-23758, Ajax.NET Professional Ajax.NET Professional (Ajax.NET Professional Deserialization of Untrusted Data Vulnerability)
  • August 26, 2026: CVE-2019-1068, Microsoft SQL Server (Microsoft SQL Server Remote Code Execution Vulnerability)
  • August 26, 2026: CVE-2015-5287, Red Hat Automatic Bug Reporting Tool (Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability)
  • August 26, 2026: CVE-2015-3246, Red Hat Libuser (Red Hat Libuser Race Condition Vulnerability)
  • August 25, 2026: CVE-2026-60004, Gitea Gitea (Gitea Code Injection Vulnerability)
  • August 24, 2026: CVE-2026-21962, Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in (Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Cont)
  • August 21, 2026: CVE-2026-73570, Synacor Zimbra Collaboration Suite (ZCS) (Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability)
  • August 20, 2026: CVE-2026-72530, TrueConf Server (TrueConf Server Code Injection Vulnerability)
  • August 20, 2026: CVE-2026-72529, TrueConf Server (TrueConf Server Missing Authentication for Critical Function Vulnerability)
  • August 19, 2026: CVE-2026-64849, MLflow MLflow (MLflow Server-Side Request Forgery Vulnerability)
  • August 18, 2026: CVE-2026-65400, Apple macOS (Apple macOS Improper Authentication Vulnerability)
  • August 18, 2026: CVE-2026-59310, Broadcom VMware vCenter (Broadcom VMware vCenter Path Traversal Vulnerability)
  • August 18, 2026: CVE-2026-55040, Microsoft SharePoint (Microsoft SharePoint Weak Authentication Vulnerability)
  • August 18, 2026: CVE-2026-33824, Microsoft Internet Key Exchange (IKE) Service Extensions (Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabili)
  • August 17, 2026: CVE-2025-62593, Ray-Project Ray (Ray-Project Ray Code Injection Vulnerability)
  • August 11, 2026: CVE-2026-72898, Metabase Metabase (Metabase SQL Injection Vulnerability)
  • August 11, 2026: CVE-2026-68820, Microsoft Windows Ancillary Function Driver for WinSock (Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerabi)
  • August 11, 2026: CVE-2026-20349, Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) (Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Thre)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.