# CISA adds four exploited flaws to KEV catalog

Published: 2026-07-21 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/68920200-2fda-546d-9c5e-08a50df30cb7/cisa-adds-four-exploited-flaws-to-kev-catalog

> CISA added four actively exploited vulnerabilities affecting DD-WRT, Langflow, and WordPress Core to its Known Exploited Vulnerabilities catalog.

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: a stack-based buffer overflow in DD-WRT (CVE-2021-27137), an inclusion of functionality from untrusted control sphere flaw in Langflow (CVE-2026-0770), and two WordPress Core issues — an interpretation conflict vulnerability (CVE-2026-63030) and a SQL injection vulnerability (CVE-2026-60137).

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting total post-exploitation control, and to verify whether systems were compromised prior to patching. While the directive is mandatory only for FCEB agencies, CISA recommends all organizations adopt similar risk-based patching practices for these vulnerabilities given their confirmed exploitation in the wild.

No specific threat actors, malware families, or campaigns are named in this advisory; it serves as a routine catalog update urging prompt patching across affected DD-WRT, Langflow, and WordPress deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2021-27137 (KEV), CVE-2026-0770 (KEV), CVE-2026-60137 (KEV), CVE-2026-63030 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/68920200-2fda-546d-9c5e-08a50df30cb7/cisa-adds-four-exploited-flaws-to-kev-catalog.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
