CISA & Critical Infrastructure Patching
Articles on urgent patching directives from CISA targeting critical infrastructure vulnerabilities, including federal agency deadlines and exploited flaws in vendor software.
CISA's Cybersecurity Directive: Three Actively Exploited Vulnerabilities in Langflow, N-central, and Apache Tomcat
CISA has ordered federal agencies to apply available mitigations for three actively exploited vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat by Friday, August 7th. The vulnerabilities — CVE-2026-9198, CVE-2026-18576, and CVE-2026-34486 — are all being leveraged by threat actors in real-world campaigns.
CISA Draws a Line in the Sand: Sunday Deadline for Two Critical Flaws
The U.S. Cybersecurity and Infrastructure Security Agency has issued Binding Operational Directive 26-04, requiring federal agencies to patch two critical vulnerabilities—CVE-2026-20230 in Cisco Unified Communications Manager Server and CVE-2026-12569 in PTC Windchill and FlexPLM—by June 28, after both were added to the Known Exploited Vulnerabilities catalog.