CISA orders federal mitigation for Langflow, N-central, and Tomcat
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered federal agencies to apply available mitigations for IBM Langflow, N-central, and Apache Tomcat, forcing urgent remediation of actively exploited vulnerabilities across government systems. The directive follows confirmed exploitation of CVE-2026-9198, CVE-2026-18576, and CVE-2026-34486 and added the flaws to CISA’s KEV catalog. Agencies were told to complete mitigation by the end of Friday, July 7th.
Related Happenings
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA KEV remediation for Android and Linux vulnerabilities
Advisory/Mitigation
H score57
First: 03.06.2026 18:36
Last: 03.06.2026 18:36
Sources 1
About this happening:
CISA’s KEV update forced federal agencies to remediate CVE-2025-48595 and CVE-2022-0492 in Android and the Linux kernel before the June 5 deadline, or...
CISA KEV remediation for Android and Linux vulnerabilities
Advisory/MitigationAbout this happening: CISA’s KEV update forced federal agencies to remediate CVE-2025-48595 and CVE-2022-0492 in Android and the Linux kernel before the June 5 deadline, or...
CISA launches KEV Nomination Form
Public Sector Action
H score38
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
H score33
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV directive for CVE-2026-20133
Public Sector Action
H score36
First: 21.04.2026 15:30
Last: 21.04.2026 15:30
Sources 1
About this happening:
On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directi...
CISA KEV directive for CVE-2026-20133
Public Sector ActionAbout this happening: On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directi...
Timeline
-
05.08.2026 18:51 1 articles · 1h ago
Chinese-speaking threat actor targets Apache Tomcat servers with reverse shells
Exploitation ObservedA Chinese-speaking threat actor tried to exploit CVE-2026-34486 in a manual campaign to plant reverse shells on nine Apache Tomcat servers.
Show sources
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51
-
05.08.2026 18:51 1 articles · 1h ago
Hackers actively exploit N-central to hijack administrative accounts
Exploitation ObservedHackers were actively exploiting CVE-2026-18576 in N-central to hijack administrative accounts without authentication, and the flaw affected all versions of N-central before 2026.3.
Show sources
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51
-
05.08.2026 18:51 2 articles · 1h ago
CISA orders federal mitigation for Langflow, N-central, and Tomcat
Legal Policy Action UpdateCISA ordered federal agencies to apply available mitigations for IBM Langflow, N-central, and Apache Tomcat by the end of Friday, July 7th after confirming threat actors were leveraging CVE-2026-9198, CVE-2026-18576, and CVE-2026-34486 and adding the flaws to the KEV catalog.
Show sources
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51