On August 5, 2026, the U.S This article explores exploited vulnerabilities kev. . Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) database by including three issues that have been detected being exploited in the wild.

The updated list of vulnerabilities is as follows: Additionally, the KEV catalog now includes an authentication bypass vulnerability known as CVE-2026-18556. This issue has been exacerbated by a partial fix implemented by N-able, which is currently tracked under CVE-2026-18577 (CVSS score: 8.2). The latest update indicates that both vulnerabilities are being actively exploited by cyber threats. No information exists regarding how the Langflow vulnerability is being exploited.

Nevertheless, security flaws within the open-source AI application development framework have been used maliciously by hackers over the past few months.

The exploitation of CVE-2026-34486 was carried out by an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan. The threat actor, based in Zhuhai, China, used DeepSeek via the Hermes Agent framework to target internet-exposed devices. When initial attempts to exploit a Langflow flaw (CVE-2026-33017, CVSS 9.8) breach failed due to restrictive configurations of the target environment, the AI agent conducted autonomous research to identify other higher-value vulnerabilities, including flaws in n8n and CVE-2023-4976 (CVE-2026-34486), CVE-2023-4977 (CVE-2026-33017), CVE-2023-4978 (CVE-2026-39987), and CVE-2023-4979 (CVE-2026-33824).

Additionally, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055) and Marimo (CVE-2026-39987).

"This actor used over 460 targets by combining both autonomous and manual methods," Palo Alto Networks Unit 42 reported. "What's intriguing is that the actor allowed DeepSeek to limit its targeting scope, presumably to save AI compute resources." The system executed hundreds of hours of manual analysis in just minutes while managing its own computational needs autonomously.

Federal Civilian Executive Branch (FCEB) agencies must apply necessary fixes by August 7, 2026, to safeguard their networks from active threats.