CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation, including two WordPress Core flaws that can be chained from SQL injection to unauthenticated remote code execution, the critical Langflow RCE CVE-2026-0770, and DD-WRT flaw CVE-2021-27137. The WordPress issues, CVE-2026-60137 and CVE-2026-63030, affect default installations and have drawn warnings from CERT-FR and NCSC-NL because public proof-of-concept code is available and broader exploitation is considered likely or imminent.
CVE-2026-60137 stems from improper sanitization of the author__not_in parameter in WP_Query when plugins or themes pass untrusted input, affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. Organizations were urged to prioritize patching those versions, update Langflow, and upgrade DD-WRT builds older than 45724; where immediate WordPress patching is not possible, defenders were advised to restrict unauthenticated access to the REST batch API endpoint, including paths such as /wp-json/batch/v1 or requests containing rest_route=/batch/v1.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-21, CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: WordPress flaws CVE-2026-60137 and CVE-2026-63030, Langflow RCE CVE-2026-0770, and DD-WRT flaw CVE-2021-27137. The KEV additions indicated confirmed active exploitation and elevated urgency for remediation.
CERT-FR and NCSC-NL warned that public proof-of-concept code was available for CVE-2026-60137 and that mass exploitation was likely or imminent. The guidance also recommended blocking unauthenticated access to the WordPress REST batch API endpoint if patching was not immediately possible.
WordPress released patched versions 6.8.6, 6.9.5, and 7.0.2 to address CVE-2026-60137, a core SQL injection flaw affecting multiple branches. The vulnerability can be chained with CVE-2026-63030 for unauthenticated remote code execution on default installations.
KEVIntel observed exploitation of Langflow CVE-2026-0770 beginning on 2026-06-27, with more than 220 attempts from 64 unique source IPs. Some attacks reportedly progressed beyond reconnaissance to deploy malware and search for AWS credentials, environment variables, and container metadata.
The CVE record for CVE-2026-0770 was published, describing a critical unauthenticated remote code execution flaw in Langflow's validate endpoint via the exec_globals parameter. The record states that Langflow 1.4.2 is affected and that successful exploitation can lead to arbitrary code execution as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcecodeby.net
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourcecve.circl.lu
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.