CISA Adds Three Actively Exploited Vulnerabilities (CVE‑2026‑9198, CVE‑2026‑18556, CVE‑2026‑34486) to KEV Catalog
What It Is — The Cybersecurity and Infrastructure Security Agency (CISA) announced that three CVEs—IBM Langflow code‑injection (CVE‑2026‑9198), N‑able N‑central authentication bypass (CVE‑2026‑18556), and Apache Tomcat missing encryption of sensitive data (CVE‑2026‑34486)—have been confirmed as actively exploited and are now listed in the agency’s Known Exploited Vulnerabilities (KEV) catalog.
Exploitability — All three flaws have documented evidence of live exploitation in the wild. CISA’s inclusion in the KEV catalog signals a high likelihood of successful attacks if unpatched.
Affected Products
- IBM Langflow – AI workflow engine, vulnerable to remote code injection.
- N‑able N‑central – Remote monitoring and management platform, vulnerable to authentication bypass via an alternate channel.
- Apache Tomcat – Widely deployed Java servlet container, vulnerable to unencrypted storage of sensitive data.
Why It Matters for Compliance & Audit Readiness
- Control Mapping – Each vulnerability maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Demonstrating timely remediation shows adherence to these controls.
- Continuous Evidence – Automated patch‑status monitoring provides audit‑ready evidence that known‑exploited flaws are being tracked and mitigated.
- Risk‑Based Prioritization – Aligning remediation with CISA’s KEV catalog satisfies the “risk‑based vulnerability management” expectation in many regulatory frameworks (e.g., NIST 800‑53, ISO 27001).
Recommended Actions
- Identify any assets running the listed products and verify exposure on public‑facing interfaces.
- Map each CVE to the relevant SOC 2 controls (CC6.1, CC7.1) in your compliance framework.
- Deploy vendor‑provided patches or mitigations immediately; document the change in your configuration management database (CMDB).
- Capture patch‑status logs and vulnerability scan results as continuous audit evidence.
- Validate that remediation was successful and that no residual exploitation indicators remain.
Source: CISA Advisory – 2026‑08‑04