Secretus logoSecretus

CISA KEV: WordPress, Langflow and DD-WRT

·8 min read

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on 21 July 2026: two WordPress Core flaws that can be chained, a Langflow remote-code issue, and a years-old DD-WRT buffer overflow. A KEV listing means CISA has evidence of exploitation in the wild. It does not, by itself, identify the actor, victim count, exploit volume, or a ransomware campaign.

The additions are CVE-2026-60137 and CVE-2026-63030 in WordPress Core, CVE-2026-0770 in Langflow, and CVE-2021-27137 in DD-WRT. CISA marks ransomware use as unknown for all four. That is enough to justify urgent asset discovery and remediation without turning incomplete public evidence into an invented breach narrative.

WordPress: an exploited two-bug path to code execution

CISA describes CVE-2026-60137 as a SQL injection condition that can arise when a plugin or theme passes untrusted input to the affected parameter. It says the issue can be chained with CVE-2026-63030, an interpretation-conflict flaw, to let an unauthenticated attacker reach remote code execution on default WordPress installations.

WordPress released 7.0.2 on 17 July and classified the release as fixing one critical and one high-severity issue. Because of the severity, the project enabled forced updates through its automatic update system for affected sites. The official backport matrix is important:

  • WordPress 7.0: update to 7.0.2 or later;
  • WordPress 6.9: update to 6.9.5 or later; both flaws apply;
  • WordPress 6.8: update to 6.8.6 or later; WordPress says only the first issue applies;
  • WordPress 7.1 beta: update to beta 2 or later;
  • versions before 6.8: WordPress says they are not affected by these two flaws.

An automatic-update policy is not proof that every site completed the update. Read the running core version from each site, including staging, forgotten campaign sites, regional instances, recovery copies, and containers built from old images. CISA gives CVE-2026-63030 a 24 July federal due date and CVE-2026-60137 a 4 August date. The shorter date should drive response to the chain as a whole.

Langflow: arbitrary code execution enters KEV

CISA says CVE-2026-0770 allows remote attackers to execute arbitrary code on affected Langflow installations. Its catalog points defenders to the Langflow 1.9.0 release, whose security-related fixes include preventing code execution through the data parameter of the build_public_tmp endpoint. CISA's federal remediation date is 24 July.

Treat an internet-reachable visual AI workflow service as an application server, not as a harmless design tool. Confirm the installed package or container version, upgrade through the supported Langflow path, rebuild derived images, and remove direct public exposure that is not required. Review authentication, reverse-proxy, application, container, and cloud control-plane logs for unexpected endpoint access or process execution.

DD-WRT: old CVE, current exploitation signal

CVE-2021-27137 is a stack-based buffer overflow in DD-WRT's UPnP handling. CISA says an unauthenticated attacker may overflow an internal buffer and trigger code execution, and points to DD-WRT changeset 45724. The catalog also warns that the affected code or protocol may appear in other products, so defenders should confirm patch status with the actual router or firmware vendor rather than rely on a product-name match alone.

Router firmware is frequently absent from endpoint inventories. Search configuration management, DHCP, wireless-controller, procurement, branch office, lab, and home-office records. Identify exposed administration and UPnP services, apply supported firmware, disable unnecessary UPnP, and replace devices that no longer have a maintained update path. CISA's date for the US federal estate is 24 July.

A defensible response sequence

  1. Find the products before scoring them. Query software, container, web, router, cloud, and procurement inventories for all four CVEs and the affected product families.
  2. Prioritise reachable systems. Start with internet-facing WordPress, Langflow, and router interfaces, then systems reachable from untrusted networks or compromised user segments.
  3. Patch to the vendor boundary. Record the old and new versions, update source, change approval, completion time, and validation evidence. Do not close a ticket because a package was merely assigned.
  4. Hunt the vulnerable interval. Look for unexpected web requests, new administrators, changed plugins or themes, new processes, scheduled tasks, altered containers, router configuration changes, and unexplained outbound connections.
  5. Escalate evidence, not fear. If indicators suggest compromise, isolate the asset, preserve logs and volatile evidence, and rotate exposed credentials from a trusted environment. Patching alone does not remove persistence established before the update.

What this means for EU and Romanian teams

CISA's binding deadlines apply to the US federal civilian executive branch, not automatically to Romanian or other EU organisations. The KEV evidence is still a strong, auditable risk-prioritisation input. Entities subject to NIS2-style risk management should be able to show how they discover affected assets, evaluate exposure, apply security updates, validate completion, and assess whether an incident occurred.

The practical lesson is broader than four CVEs: vulnerability feeds must connect to an owned asset, a reachable deployment, an accountable person, a tested remediation, and retained evidence. A KEV alert without that operational chain is only another line in a dashboard.

Sources

Share a secret the safe way

End-to-end encrypted, one-time links — free, no account needed.

Try Secretus