CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation, including two WordPress Core flaws that can be chained from SQL injection to unauthenticated remote code execution, the critical Langflow RCE CVE-2026-0770, and DD-WRT flaw CVE-2021-27137. The WordPress issues, CVE-2026-60137 and CVE-2026-63030, affect default installations and have drawn warnings from CERT-FR and NCSC-NL because public proof-of-concept code is available and broader exploitation is considered likely or imminent.
CVE-2026-60137 stems from improper sanitization of the author__not_in parameter in WP_Query when plugins or themes pass untrusted input, affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. Organizations were urged to prioritize patching those versions, update Langflow, and upgrade DD-WRT builds older than 45724; where immediate WordPress patching is not possible, defenders were advised to restrict unauthenticated access to the REST batch API endpoint, including paths such as /wp-json/batch/v1 or requests containing rest_route=/batch/v1.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-21, CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: WordPress flaws CVE-2026-60137 and CVE-2026-63030, Langflow RCE CVE-2026-0770, and DD-WRT flaw CVE-2021-27137. The KEV additions indicated confirmed active exploitation and elevated urgency for remediation.
CERT-FR and NCSC-NL warned that public proof-of-concept code was available for CVE-2026-60137 and that mass exploitation was likely or imminent. The guidance also recommended blocking unauthenticated access to the WordPress REST batch API endpoint if patching was not immediately possible.
WordPress released patched versions 6.8.6, 6.9.5, and 7.0.2 to address CVE-2026-60137, a core SQL injection flaw affecting multiple branches. The vulnerability can be chained with CVE-2026-63030 for unauthenticated remote code execution on default installations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.