cisa-kev
CISA KEVKeeps: CVE id, vendor, due date
CVE: CVE-2026-9198 Vendor/project: IBM Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-94 Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deploy
- 2026-08-04CISA KEV: Apache / Tomcat / Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE: CVE-2026-34486 Vendor/project: Apache Product: Tomcat Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-311 Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. Required action: Apply
CVE: CVE-2026-18556 Vendor/project: N-able Product: N-central Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-288 N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Required action: App