CISA KEV: Update TrueConf Server Now
CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog. Update self-hosted servers to the current vendor security release and validate services.

CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog. Update self-hosted servers to the current vendor security release and validate services.
CISA added Apache Tomcat CVE-2026-34486 to KEV. Review use of the affected clustering encryption feature and update Tomcat 9, 10, or 11 to the fixed maintenance release.
CISA added Langflow CVE-2026-0770 to KEV. Update affected AI workflow servers to 1.9.0 or later, restrict access, and review connected credentials.
Review Coolify CVE-2026-15507 with a backup-first self-hosted server checklist for versions 4.1.1 and older, access controls, tokens, deployments, logs, and hosted apps.
Use WHM Security Advisor and Configure Security Policies to review API two-factor protection after cPanel updates, verify automation owners, and document exceptions.
Test aaPanel 8.17.0 beta with backup, rollback, website, database, SSL, WAF, Docker, and monitoring checks before production.
CISA added Langflow CVE-2026-55255 to KEV. Update to 1.9.2 or later, restrict exposed builders, and review tenant boundaries.
CISA updated CVE-2025-3248 for Langflow to known ransomware campaign use. Check exposed Langflow, upgrade to 1.3.0 or later, and review connected secrets.
Updated July 2: Webmin 2.650, Usermin 2.550, and Webmin 2.651 add security-relevant fixes, Certbot renewal fixes, and admin-panel verification steps.
Patch NGINX 1.31.2 or 1.30.3 for June 2026 security fixes. Check HTTP/3, proxy and gRPC paths, charset handling, config validation, safe reloads, logs, CDN behavior, and rollback planning.