Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-9198 IBM Langflow Code Injection Vulnerability • CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments. N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams to centrally administer servers, workstations, network devices, and other managed assets.

·Rapid7 Blog
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-18556 - N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-18556 Detail - National Institute of Standards and Technology (.gov)

CVE-2026-18556 Detail National Institute of Standards and Technology (.gov)

·NVD
Read →

You've reached the end of current stories for this search.