Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. CISA Adds DD-WRT, Langflow, and WordPress Flaws to Its Known Exploited Vulnerabilities Catalog: A Growing Concern for Cybersecurity


U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog due to their significant security vulnerabilities, emphasizing the need for organizations to prioritize vulnerability management and patching to prevent potential attacks.

  • DD-WRT, Langflow, and WordPress have been added to the U.S. CISA's KEV catalog due to significant security vulnerabilities.
  • CVE-2021-27137 affects DD-WRT with a buffer overflow vulnerability in UPnP handling functionality.
  • CVE-2026-0770 is a critical remote code execution vulnerability affecting Langflow.
  • WordPress Core has two critical vulnerabilities, wp2shell (CVE-2026-63030) and SQL injection (CVE-2026-60137), with public proof-of-concept exploits available.
  • The U.S. CISA has ordered federal agencies to fix these flaws by July 24, 2026, except for CVE-2026-60137, which must be fixed by August 4.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These additions highlight the ongoing threat landscape in the cybersecurity sector, emphasizing the need for organizations to prioritize vulnerability management and patching.

    DD-WRT, Langflow, and WordPress are three popular open-source projects that have been identified as having significant security vulnerabilities. The U.S. CISA has added these flaws to its KEV catalog due to their potential impact on federal information systems and networks.

    The first issue added to the catalog is CVE-2021-27137, a buffer overflow vulnerability affecting DD-WRT before version 45724. This flaw exists in the UPnP handling functionality (ssdp.c) due to an unsafe strcpy operation in the ssdp_msearch function. An unauthenticated remote attacker could exploit this issue by sending a specially crafted M-SEARCH request to trigger a buffer overflow and potentially execute arbitrary code.

    The second issue added to the catalog is CVE-2026-0770, a critical remote code execution vulnerability affecting Langflow. This flaw exists in the handling of the exec_globals parameter in the validate endpoint, where the application improperly loads functionality from an untrusted control sphere. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code with root privileges on affected systems.

    Regarding WordPress issues added to the catalog, public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. These flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.

    CVE-2026-63030 is a REST API batch-route confusion bug introduced in WordPress 6.9. This flaw allows an attacker to bypass WordPress's security features and gain unauthorized access to sensitive data.

    CVE-2026-60137 is a high-severity SQL injection flaw in the author__not_in parameter of WP_Query, affecting default WordPress installations.

    The U.S. CISA has ordered federal agencies to fix these flaws by July 24, 2026, except for CVE-2026-60137, which must be fixed by August 4. Experts recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure to prevent potential attacks.

    In light of these recent additions, it is essential for organizations to prioritize vulnerability management and patching. The U.S. CISA's efforts to identify and mitigate known exploited vulnerabilities serve as a reminder of the importance of staying informed about emerging threats and taking proactive measures to protect against them.

    The impact of these newly added vulnerabilities cannot be overstated, particularly in high-risk environments such as federal agencies and organizations with critical infrastructure. The need for vigilance and prompt action is underscored by the U.S. CISA's efforts to inform and educate the public about the latest threats.

    Organizations must take immediate action to address these identified vulnerabilities and ensure that their systems are protected against potential attacks. By doing so, they can mitigate the risk of data breaches and maintain the integrity of their networks.

    In conclusion, the recent additions to the U.S. CISA's KEV catalog highlight the growing concern for cybersecurity in the industry. As new threats emerge, it is essential for organizations to prioritize vulnerability management and patching to protect against potential attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-CISA-Adds-DD-WRT-Langflow-and-WordPress-Flaws-to-Its-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml

  • https://securityaffairs.com/195782/security/u-s-cisa-adds-dd-wrt-langflow-and-wordpress-flaws-to-its-known-exploited-vulnerabilities-catalog.html


  • Published: Wed Jul 22 12:18:55 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us