CISA adds four exploited flaws to KEV catalog
CISA added four actively exploited vulnerabilities affecting DD-WRT, Langflow, and WordPress Core to its Known Exploited Vulnerabilities catalog.
CISA has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: a stack-based buffer overflow in DD-WRT (CVE-2021-27137), an inclusion of functionality from untrusted control sphere flaw in Langflow (CVE-2026-0770), and two WordPress Core issues — an interpretation conflict vulnerability (CVE-2026-63030) and a SQL injection vulnerability (CVE-2026-60137).
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting total post-exploitation control, and to verify whether systems were compromised prior to patching. While the directive is mandatory only for FCEB agencies, CISA recommends all organizations adopt similar risk-based patching practices for these vulnerabilities given their confirmed exploitation in the wild.
No specific threat actors, malware families, or campaigns are named in this advisory; it serves as a routine catalog update urging prompt patching across affected DD-WRT, Langflow, and WordPress deployments.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free