THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, specifically affecting DD-WRT, Langflow, and WordPress. Key vulnerabilities include:
1. **CVE-2021-27137**: A stack-based buffer overflow in DD-WRT with a CVSS score of 8.1 that allows remote attackers to potentially execute arbitrary code.
2. **CVE-2026-0770**: A critical remote code execution vulnerability in Langflow with a CVSS score of 9.8, enabling attackers to execute code with root privileges.
3. **CVE-2026-63030**: A REST API bug in WordPress, also with a CVSS score of 9.8, leading to remote code execution.
4. **CVE-2026-60137**: A SQL injection vulnerability with a CVSS score of 5.9 affecting WordPress.
Immediate action is urged for organizations using affected versions, especially WordPress, due to the existence of public exploit proofs and the potential for widespread attacks. CISA mandates federal agencies to address these vulnerabilities by July 24, 2026, with specific actions due for WordPress vulnerabilities by August 4, 2026.