TL;DR
CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog on August 4, 2026. The headline bug is an N-able N-central authentication bypass, now exploited in the wild against MSP platforms. Federal agencies must patch all three by August 7.
- Product: N-able N-central, IBM Langflow OSS +1
- Vulnerabilities: 3 flaws (CVE-2026-18556, CVE-2026-9198, CVE-2026-34486)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
- Status: 3 exploited; patches available
- Action: Update to 11.0.21, 10.1.54, 9.0.117 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-9198 | 9.8 | CWE-94 | — | Exploited |
| CVE-2026-34486 | 7.5 | CWE-311 | 11.0.21, 10.1.54, 9.0.117 | Exploited |
| CVE-2026-18556 | 7.4 | Unauthenticated administrative account takeover | — | Exploited |
Why it matters
N-able N-central is a remote monitoring and management platform used by managed service providers. So one breach can cascade to many client networks. That makes it a high-value target. A KEV listing also means CISA has proof of real attacks, not just theory. The other two flaws hit IBM Langflow and Apache Tomcat, both widely deployed.
N-central exploited in the wild
CVE-2026-18556 is an authentication bypass in N-able N-central. Attackers can reach the management interface without valid credentials. N-able says exploitation began on July 31 as a zero-day. A related bypass, CVE-2026-18577, followed an incomplete fix. Sophos investigated one confirmed intrusion. It reports “a single compromised organization” and “no evidence that compromises are widespread.” In that case, the attacker used the hijacked N-central server to reach backup servers and domain controllers. Then they created a rogue “veeam” domain account, reset admin passwords, and deployed several remote-access tools. They also disguised a Cloudflare tunnel as a Microsoft update to hold access. N-able flagged one clue for defenders. A file named svchost.exe inside a user’s Documents folder can signal a compromise. Teams should also watch for unexpected remote-access tools.
The other two flaws
CVE-2026-9198 is a critical code-injection bug in IBM Langflow, rated CVSS 9.8. Unauthenticated attackers can chain two API endpoints to run code on default installs. CVE-2026-34486 affects Apache Tomcat and weakens data encryption, rated 7.5.
Affected versions and patches
N-central through 2026.1 is affected, so apply N-able’s hotfix at once. Langflow OSS 1.0.0 through 1.10.0 is vulnerable. Tomcat users should move to 11.0.21, 10.1.54, or 9.0.117. Before closing out, hunt for rogue accounts and unauthorized RMM installs.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.