CISA's Latest KEV Update Puts WordPress and Langflow at the Front of the Patch Queue
Cloud

CISA's Latest KEV Update Puts WordPress and Langflow at the Front of the Patch Queue

CISA added actively exploited WordPress Core, Langflow, and DD-WRT vulnerabilities to its KEV Catalog. Here is how to prioritize inventory, exposure, and remediation.

3 min readJuly 23, 2026
Back to News

CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog on July 21, 2026, based on evidence of active exploitation. The update names two WordPress Core flaws, one Langflow flaw, and one DD-WRT flaw. If you run any of these products, this is a change in patch priority, not another item for a quarterly report.

TL;DR

  • CISA's July 21 update covers WordPress Core, Langflow, and DD-WRT flaws that the agency says are being exploited.
  • The alert does not provide affected versions or vendor fixes. Asset owners still need to check the relevant vendor guidance.
  • Start with exposure. Find matching systems, check whether attackers can reach them, and look for signs of compromise before closing the issue.

What CISA added

The four entries are:

  • CVE-2026-60137, a WordPress Core SQL injection vulnerability.
  • CVE-2026-63030, a WordPress Core interpretation conflict vulnerability.
  • CVE-2026-0770, a Langflow inclusion of functionality from an untrusted control sphere vulnerability.
  • CVE-2021-27137, a DD-WRT stack-based buffer overflow vulnerability.

CISA says these flaws are frequent attack vectors and pose significant risk to the federal enterprise. That separates this notice from a theoretical severity score. The evidence of exploitation makes one question urgent: does your environment contain an affected system that attackers can reach?

The federal rule has a narrower scope. BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize KEV flaws on public assets that could give an attacker full control. CISA also encourages every organization to use risk-based vulnerability management and prioritize KEV fixes.

What this means for your stack

For WordPress, check the core version on every production, staging, and old campaign site. Check how core updates are applied and who owns an exception when an update is delayed. Metrotechs analysis: a plugin inventory alone cannot show whether the two Core CVEs apply.

For Langflow, map each deployment before deciding the response. Check its public routes, authentication, and access to models, data stores, APIs, and credentials. Metrotechs analysis: if an affected instance has broad downstream access, isolation and credential review may matter as much as installing a fix.

For DD-WRT, include branch offices, lab networks, and unmanaged edge devices in the inventory. The CVE identifier begins with 2021, but CISA added it on July 21 after finding exploitation evidence. For prioritization, treat its age as context, not a reason to delay.

The July 21 CISA notice does not list affected versions, patch releases, attack indicators, or product-specific fixes. Do not guess from the vulnerability name. Review the KEV entry and relevant vendor advisory to confirm scope and remediation. Keep that evidence with the ticket.

The decision to make now

Decide which systems need immediate isolation, which can move to a verified fix, and which need more product detail. Put public systems, privileged systems, and systems tied to sensitive data first.

Do not let a successful patch close the investigation by itself. CISA says the federal rule includes checks for whether attackers compromised a system before a patch was applied. For teams outside the federal scope, that is still a sound operating rule for an actively exploited flaw.

Concrete next step: pull the WordPress Core, Langflow, and DD-WRT inventory today. Next, check affected versions and vendor guidance with a named owner. Record exposure and access paths. Then set a deadline for patching, isolation, or replacement.

Sources and supporting resources
Previous
OpenAI's Evaluation Incident Shows the Gap in AI Sandbox Security
Next
Oracle 26B Expands Contract Manufacturer Visibility for Process Manufacturing