Skip to content
eastbaycyber

CISA Adds 4 Known Exploited Vulnerabilities to Catalog (July 21, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On July 21, 2026, CISA added 4 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-60137, CVE-2026-63030, CVE-2026-0770, CVE-2021-27137. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-60137: WordPress Core SQL Injection Vulnerability

WordPress · Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Federal due date
2026-08-04
Ransomware use
Unknown
Added
2026-07-21

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability

WordPress · Core

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Federal due date
2026-07-24
Ransomware use
Unknown
Added
2026-07-21

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read our explainer · NVD record

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow · Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Federal due date
2026-07-24
Ransomware use
Unknown
Added
2026-07-21

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT · DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

Federal due date
2026-07-24
Ransomware use
Unknown
Added
2026-07-21

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

Also added to KEV in July 2026

  • July 29, 2026: CVE-2026-20316, Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)
  • July 27, 2026: CVE-2026-16812, Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)
  • July 27, 2026: CVE-2025-68686, Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vuln)
  • July 22, 2026: CVE-2026-50522, Microsoft SharePoint (Microsoft SharePoint Deserialization of Untrusted Data Vulnerability )
  • July 22, 2026: CVE-2026-16232, Check Point SmartConsole (Check Point SmartConsole Improper Authentication Vulnerability)
  • July 16, 2026: CVE-2026-58644, Microsoft SharePoint (Microsoft SharePoint Deserialization of Untrusted Data Vulnerability)
  • July 16, 2026: CVE-2026-39808, Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)
  • July 16, 2026: CVE-2026-25089, Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)
  • July 15, 2026: CVE-2026-46817, Oracle E-Business Suite (Oracle E-Business Suite Improper Privilege Management Vulnerability)
  • July 15, 2026: CVE-2023-4346, KNX Association KNX Protocol Connection Authorization Option 1 (KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictiv)
  • July 14, 2026: CVE-2026-56164, Microsoft SharePoint Server (Microsoft SharePoint Server Missing Authentication for Critical Function Vulnera)
  • July 14, 2026: CVE-2026-56155, Microsoft Active Directory Federation Services (Microsoft Active Directory Federation Services Insufficient Granularity of Acces)
  • July 14, 2026: CVE-2026-15410, SonicWall SMA1000 Appliances (SonicWall SMA1000 Appliances Code Injection Vulnerability)
  • July 14, 2026: CVE-2026-15409, SonicWall SMA1000 Appliances (SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability)
  • July 13, 2026: CVE-2008-4128, Cisco IOS (Cisco IOS Cross-Site Request Forgery Vulnerability)
  • July 10, 2026: CVE-2026-56291, Balbooa Forms (Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability)
  • July 10, 2026: CVE-2026-48939, iCagenda iCagenda (iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability)
  • July 7, 2026: CVE-2026-56290, Joomlack Page Builder (Joomlack Page Builder Improper Access Control Vulnerability)
  • July 7, 2026: CVE-2026-55255, Langflow Langflow (Langflow Authorization Bypass Through User-Controlled Key Vulnerability)
  • July 7, 2026: CVE-2026-48908, JoomShaper SP Page Builder (JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulne)
  • July 7, 2026: CVE-2026-48282, Adobe ColdFusion (Adobe ColdFusion Path Traversal Vulnerability)
  • July 1, 2026: CVE-2026-45659, Microsoft SharePoint Server (Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.