Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA orders federal mitigation for Langflow, N-central, and Tomcat

Public Sector Action
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

CISA ordered federal agencies to apply available mitigations for IBM Langflow, N-central, and Apache Tomcat, forcing urgent remediation of actively exploited vulnerabilities across government systems. The directive follows confirmed exploitation of CVE-2026-9198, CVE-2026-18576, and CVE-2026-34486 and added the flaws to CISA’s KEV catalog. Agencies were told to complete mitigation by the end of Friday, July 7th.

Related Happenings

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...

CISA KEV remediation for Android and Linux vulnerabilities

Advisory/Mitigation
H score57 First: 03.06.2026 18:36 Last: 03.06.2026 18:36 Sources 1

About this happening: CISA’s KEV update forced federal agencies to remediate CVE-2025-48595 and CVE-2022-0492 in Android and the Linux kernel before the June 5 deadline, or...

CISA launches KEV Nomination Form

Public Sector Action
H score38 First: 21.05.2026 15:00 Last: 21.05.2026 15:00 Sources 1

About this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....

CISA KEV order for Copy Fail on federal Linux devices

Public Sector Action
H score33 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...

CISA KEV directive for CVE-2026-20133

Public Sector Action
H score36 First: 21.04.2026 15:30 Last: 21.04.2026 15:30 Sources 1

About this happening: On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directi...

Timeline

  1. 05.08.2026 18:51 1 articles · 1h ago

    Hackers actively exploit N-central to hijack administrative accounts

    Exploitation Observed

    Hackers were actively exploiting CVE-2026-18576 in N-central to hijack administrative accounts without authentication, and the flaw affected all versions of N-central before 2026.3.

    Show sources
  2. 05.08.2026 18:51 2 articles · 1h ago

    CISA orders federal mitigation for Langflow, N-central, and Tomcat

    Legal Policy Action Update

    CISA ordered federal agencies to apply available mitigations for IBM Langflow, N-central, and Apache Tomcat by the end of Friday, July 7th after confirming threat actors were leveraging CVE-2026-9198, CVE-2026-18576, and CVE-2026-34486 and adding the flaws to the KEV catalog.

    Show sources