CiberLATAMbywhalemate

CISA adds CVE-2026-34486 to KEV catalog

CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in Apache Tomcat. The agency also added two other exploited flaws, including CVE-2026-9198 in Langflow, and gave US civilian federal agencies until Aug. 7 to remediate them.

CISA has added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a vulnerability in Apache Tomcat. The same update also brought in two other actively exploited flaws, including CVE-2026-9198 in Langflow.

Available reporting indicates that the U.S. agency gave U.S. civilian federal agencies a remediation deadline for the vulnerabilities added to KEV, due on 2026-08-07. That puts the official response on a short timeline for systems affected by these issues.

Apache Tomcat under active exploitation

CISA’s listing identifies CVE-2026-34486 as a known vulnerability that is being actively exploited in Apache Tomcat. In KEV trackers, the flaw also appears among the weaknesses already being used in attacks.

f4n6 also reported that the updated SSVC status for CVE-2026-34486 now reflects active exploitation and full technical impact. The same report says the vulnerability affects only Tomcat 11.0.20, 10.1.53 and 9.0.116, with fixes in 11.0.21, 10.1.54 and 9.0.117.

The f4n6 reference also mentions public proof-of-concept activity for CVE-2026-34486, which reinforces the view that the issue is being operationalized by attackers. The available NVD entry and KEV trackers match the association with Apache Tomcat.

Langflow also entered KEV

CISA added CVE-2026-9198 to the catalog alongside CVE-2026-34486, and KEV trackers list it as a known, actively exploited vulnerability tied to IBM Langflow OSS. The inclusion of both flaws in the same update confirms that the agency saw real exploitation activity in more than one product exposed in corporate environments.

The move leaves U.S. civilian federal agencies with a remediation window ending on Aug. 7 for the cases covered in the reporting. For organizations running exposed infrastructure, the KEV update serves as an immediate priority signal for public-facing or internet-accessible systems.

Sources

View all