CISA Adds Four Vulnerabilities to KEV Catalog Aug 6 2026

CISA Adds Four Vulnerabilities to KEV Catalog Aug 6 2026


Four Newly Added KEV Entries Reinforce the Growing Focus on Enterprise Management, AI, Middleware, and DevSecOps Platforms

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog with four vulnerabilities affecting N-able N-central, IBM Langflow, Apache Tomcat, and JetBrains TeamCity. Their inclusion confirms that these flaws are being actively exploited in the wild, making them immediate priorities for remediation.

This latest KEV update demonstrates that attackers are increasingly targeting platforms that provide centralized management, AI workflow orchestration, enterprise application hosting, and software development capabilities. A successful compromise of these systems can provide privileged access, facilitate lateral movement, or even enable software supply-chain attacks.

CVE-2026-9198 – IBM Langflow Code Injection

Overview

IBM Langflow, a visual orchestration platform for building Large Language Model (LLM) workflows, contains a critical code injection vulnerability that can allow an unauthenticated attacker to execute arbitrary code on a vulnerable server.

As organizations increasingly integrate Langflow with cloud AI services, vector databases, APIs, and internal business applications, compromise of the orchestration platform can provide attackers with broad access to enterprise AI environments.

Potential Impact

  • Remote code execution
  • Complete server compromise
  • Exposure of API keys and LLM credentials
  • Theft of environment variables and secrets
  • Unauthorized access to connected enterprise systems

Why It Matters

AI orchestration platforms are rapidly becoming part of the enterprise attack surface. Their integration with multiple backend services makes them attractive targets for threat actors seeking privileged access and sensitive data.

CVE-2026-18556 – N-able N-central Authentication Bypass

Overview

This vulnerability allows attackers to bypass authentication using an alternate path or channel, enabling unauthorized access to the N-able N-central Remote Monitoring and Management (RMM) platform.

N-central is widely used by Managed Service Providers (MSPs) and enterprise IT teams to administer thousands of endpoints. A successful attack against the management server can significantly amplify the attacker’s reach.

Potential Impact

  • Administrative account takeover
  • Unauthorized remote management
  • Endpoint compromise
  • Credential theft
  • Ransomware deployment across managed devices

Why It Matters

RMM platforms inherently operate with elevated privileges. Compromising the management plane enables attackers to pivot rapidly across customer or enterprise environments, making these systems high-value targets.

CVE-2026-34486 – Apache Tomcat Missing Encryption of Sensitive Data

Overview

Apache Tomcat contains a vulnerability related to the missing encryption of sensitive data, potentially exposing confidential information under certain deployment scenarios.

Although this issue is not a traditional remote code execution vulnerability, the exposure of sensitive information can significantly aid attackers during reconnaissance or subsequent exploitation.

Potential Impact

  • Sensitive data disclosure
  • Credential exposure
  • Session information leakage
  • Increased attack surface for follow-on attacks

Why It Matters

Apache Tomcat underpins countless enterprise Java applications across government, finance, healthcare, and critical infrastructure. Even information disclosure vulnerabilities can have substantial downstream security implications when exploited in combination with other weaknesses.

CVE-2026-63077 – JetBrains TeamCity Deserialization of Untrusted Data

Overview

JetBrains TeamCity contains a deserialization of untrusted data vulnerability (CWE-502) that could allow an unauthenticated attacker to achieve remote code execution via the agent polling protocol.

Because TeamCity is a central component of many CI/CD pipelines, exploitation could compromise the integrity of software development and deployment processes.

Potential Impact

  • Unauthenticated remote code execution
  • CI/CD server compromise
  • Source code theft
  • Build pipeline manipulation
  • Malicious code injection into software releases
  • Software supply-chain compromise

Why It Matters

Build servers represent one of the most sensitive assets within modern enterprises. A compromised CI/CD platform can allow attackers to distribute malicious software through trusted update mechanisms, making TeamCity an attractive target for sophisticated threat actors.

Why This KEV Update Matters

The latest additions illustrate a clear evolution in attacker priorities:

  • AI Platforms: IBM Langflow highlights the growing focus on AI infrastructure.
  • Management Infrastructure: N-able N-central provides privileged access across enterprise environments.
  • Enterprise Middleware: Apache Tomcat continues to be a foundational component for mission-critical applications.
  • Software Supply Chain: JetBrains TeamCity remains a high-value target due to its role in software development pipelines.

Rather than targeting individual endpoints, adversaries are increasingly pursuing platforms that provide centralized control, privileged access, and opportunities for large-scale compromise.

Recommended Actions

Organizations should immediately:

  • Inventory all deployments of IBM Langflow, N-able N-central, Apache Tomcat, and JetBrains TeamCity.
  • Apply the latest vendor patches and security updates.
  • Review authentication, application, and administrative logs for indicators of compromise.
  • Restrict internet exposure of administrative interfaces wherever possible.
  • Validate that EDR, SIEM, IDS/IPS, and vulnerability management tools detect exploitation attempts associated with these CVEs.
  • Prioritize threat hunting on internet-facing instances and critical infrastructure hosting these products.
  • Incorporate these vulnerabilities into emergency patch management workflows due to their confirmed active exploitation.

Key Takeaway

The latest KEV additions reinforce a significant shift in the threat landscape. Attackers are increasingly targeting enterprise management platforms, AI orchestration tools, Java middleware, and CI/CD infrastructure—systems that offer broad operational impact and privileged access.

For defenders, the lesson is clear: confirmed exploitation should drive remediation priorities over severity scores alone. Continuous monitoring of the KEV Catalog, rapid patch deployment, and proactive threat hunting remain essential to reducing organizational risk before attackers can establish persistence or escalate their access.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.