Nothing says "Monday" quite like CISA adding fresh entries to its Known Exploited Vulnerabilities catalog, that ever-growing list of software flaws attackers are already using in the wild — not "could theoretically," but actively, right now, while you're reading this sentence.
Three Bugs, Zero Chill
First up is CVE-2026-9198 in Langflow, a code injection flaw scoring a near-maximum 9.8 on the CVSS scale that lets unauthenticated attackers achieve full remote code execution. It's already been hit with over 650 exploitation attempts from 244 attacker IPs spread across 41 countries — the fix landed in version 1.10.1 back in July.
Next is CVE-2026-34486 in Apache Tomcat, a missing-encryption bug that bypasses the EncryptInterceptor protection on cluster communications; Chinese-speaking threat actors have reportedly been weaponizing it against targets in over 100 countries. Rounding things out are two N-able N-central authentication bypass flaws, CVE-2026-18556 and CVE-2026-18577, both rated 8.2, where the first patch attempt didn't fully close the door and needed a follow-up fix.
The Clock Is Already Ticking
CISA has given federal civilian agencies until August 7, 2026 to patch these or disconnect the affected systems — which, depending on when you're reading this, might already be in the rearview mirror. That deadline is a floor, not a ceiling: anyone running these tools, federal or not, is a target the moment a CVE goes public and exploit code starts circulating.
The pattern worth noticing isn't any single CVE — it's the speed. Hundreds of exploitation attempts within weeks of disclosure, and a "fixed" vulnerability that needed a second patch to actually be fixed. Attackers don't wait for your change-management meeting, and increasingly, neither do the bugs.
If any of these three names — Langflow, Tomcat, or N-central — live on your network, this is your sign to stop reading and go check your patch logs.
This is exactly the kind of thing our free Developer's Security Checklist covers — or skip the reading and talk to us.
Source: The Hacker News