Posting Date: 2026/08/13

【Vulnerability Alert】CISA Adds 6 Known Exploited Vulnerabilities to KEV Catalog (2026/08/03-2026/08/09)

  • Subject: 【Vulnerability Alert】CISA Adds 6 Known Exploited Vulnerabilities to KEV Catalog (2026/08/03-2026/08/09)


  • Description:
    • Forwarded Cybersecurity Alert from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202608-00000009
    • 【CVE-2026-18556】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
    • 【Ransomware Use: Unknown】 An authentication bypass vulnerability exists in N-able N-central, allowing attackers to bypass authentication mechanisms using an alternate path or channel.
    • 【CVE-2026-18577】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
    • 【Ransomware Use: Unknown】 An authentication bypass vulnerability exists in N-able N-central, allowing attackers to bypass authentication mechanisms via an alternate path or channel and subsequently take over accounts in N-central. This vulnerability stems from an incomplete patch issued for CVE-2026-18556.
    • 【CVE-2026-34486】Apache Tomcat Missing Encryption of Sensitive Data Vulnerability (CVSS v3.1: 7.5)
    • 【Ransomware Use: Unknown】 A missing encryption of sensitive data vulnerability exists in Apache Tomcat, allowing attackers to exploit it to bypass EncryptInterceptor. This vulnerability can be chained with CVE-2025-24813.
    • 【CVE-2026-9198】IBM Langflow Code Injection Vulnerability (CVSS v3.1: 9.8)
    • 【Ransomware Use: Unknown】 A code injection vulnerability exists in Langflow, allowing unauthenticated attackers to achieve full remote code execution in default Langflow deployment environments.
    • 【CVE-2026-63077】JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
    • 【Ransomware Use: Unknown】 A deserialization of untrusted data vulnerability exists in JetBrains TeamCity, allowing attackers to execute remote code unauthenticated via the agent polling protocol.
    • 【CVE-2026-8037】Progress LoadMaster Command Injection Vulnerability (CVSS v3.1: 9.6)
    • 【Ransomware Use: Unknown】 A command injection vulnerability exists in Progress LoadMaster, allowing unauthenticated attackers to execute arbitrary commands on LoadMaster devices by leveraging unsanitized inputs across multiple command endpoints.
  • Affected Systems:
  • Recommendations:

Computer and Communication Center
Network System Division