securityonline.info 7/21/2026, 6:11:47 PM · external

CISA warns of active exploits in WordPress, Langflow, DDWRT

CISA warns of active exploits in WordPress, Langflow, DDWRT
Developing story vulnerability 3 articles tracked
WordPress core flaw chain (CVE-2026-60137, CVE-2026-63030) exploited for remote code execution

ON July 21, 2026, CISA added four exploited vulnerabilities to its KEV catalog, highlighting critical flaws in WordPress, Langflow, and an older DD-WRT router bug. These vulnerabilities can be actively exploited, necessitating immediate action from federal agencies and private organizations.

The vulnerabilities include:

1. **WordPress**: Two core bugs (CVE-2026-63030 and CVE-2026-60137) allow SQL injection leading to remote code execution.

2. **Langflow**: CVE-2026-0770 is a critical unauthenticated remote code execution flaw.

3. **DD-WRT**: CVE-2021-27137, a stack buffer overflow vulnerability, affects older router versions.

Users are advised to update WordPress to specific patched versions and to address Langflow and DD-WRT vulnerabilities. Quick patching is essential to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline