CISA Adds Langflow (CVSS 9.8), N-central, and Apache Tomcat to KEV — Three Flaws Under Active Exploitation
On August 5, 2026, CISA added three critical vulnerabilities to its KEV catalog: CVE-2026-9198 in IBM Langflow (CVSS 9.8), CVE-2026-18576 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. Federal agencies must patch immediately.