CISA has flagged three vulnerabilities as actively exploited, adding them to its Known Exploited Vulnerabilities Catalog. The most identity-relevant is CVE-2026-18556, an authentication bypass in N-able N-central that uses an alternate path or channel to circumvent access controls. N-central is a widely deployed remote monitoring and management platform used by MSPs, so an auth bypass can grant attackers privileged control across many downstream customer environments.
The other two entries are CVE-2026-9198 (IBM Langflow code injection) and CVE-2026-34486 (Apache Tomcat missing encryption of sensitive data), the latter potentially exposing credentials or session data in transit. Under BOD 26-04, federal agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets, especially those that grant full post-exploitation control.
What to take away: Auth bypass flaws in management tooling like N-central are prime targets for lateral movement and credential theft. Organizations should patch immediately, review N-central access logs for anomalous authentication, and rotate any credentials that may have been exposed.