ON July 21, 2026, CISA added four exploited vulnerabilities to its KEV catalog, highlighting critical flaws in WordPress, Langflow, and an older DD-WRT router bug. These vulnerabilities can be actively exploited, necessitating immediate action from federal agencies and private organizations.
The vulnerabilities include:
1. **WordPress**: Two core bugs (CVE-2026-63030 and CVE-2026-60137) allow SQL injection leading to remote code execution.
2. **Langflow**: CVE-2026-0770 is a critical unauthenticated remote code execution flaw.
3. **DD-WRT**: CVE-2021-27137, a stack buffer overflow vulnerability, affects older router versions.
Users are advised to update WordPress to specific patched versions and to address Langflow and DD-WRT vulnerabilities. Quick patching is essential to mitigate risks.