CISA Flags Three More Actively Exploited Software Flaws — Is Your Business Affected?
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three new security flaws to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively used by attackers. The affected products are IBM Langflow (code injection), N-able N-central (authentication bypass), and Apache Tomcat (missing encryption of sensitive data).
While CISA's directive requiring rapid fixes technically applies to US federal agencies, the KEV Catalog is a widely trusted resource used by IT teams and managed service providers worldwide to prioritise patching. These vulnerabilities are especially attractive to cybercriminals because they can be exploited with proven, working techniques rather than theoretical risk, making them a common entry point for ransomware and data breaches.
Australian small businesses using any of these products, or relying on IT providers that manage N-able N-central or Apache Tomcat systems, should check with their vendors or IT support about patch status immediately. Even businesses without these exact products should treat this as a reminder that unpatched software remains one of the easiest ways attackers gain access to systems.