DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 04:57:08ZSOURCES: 14CRITICAL: 43
⚠ ACTIVE ALERTS
@TalosSecurity CRITICAL — Cl0p (aka Graceful Spider/Lace Tempest) affiliate campaign against PTC Windchill/FlexPLM… /// @MandiantThreats CRITICAL — Active Cl0p double-extortion campaign exploiting CVE-2026-12569 (PTC Windchill/FlexPLM… /// @GossiTheDog CRITICAL — SonicWall SMA1000 situation is worse than the July 14 advisory suggested. Volexity traced… /// @MsftSecIntel CRITICAL — THREAT UPDATE: CVE-2026-6875 (ServiceNow AI Platform pre-auth sandbox-escape RCE, CVSS… /// @MalwareHunterTeam CRITICAL — Fastjson CVE-2026-16723 (CVSS 9.0) — active exploitation confirmed by ThreatBook and…
43Critical Threats
19Active CVEs
11IOCs Tracked
12New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // CISA-KEV-2026-07-21 // PUBLISHED 2026-07-21

CISA Adds Four Known Exploited Vulnerabilities to Catalog — DD-WRT, Langflow, WordPress Core (July 21, 2026)

CISA added four actively exploited vulnerabilities to the KEV catalog on July 21, 2026: a DD-WRT stack-based buffer overflow enabling unauthenticated RCE via UPnP (CVE-2021-27137), a Langflow untrusted control sphere inclusion flaw (CVE-2026-0770), and two chained WordPress Core flaws — an interpretation conflict enabling SQL injection (CVE-2026-63030) and a SQL injection vulnerability (CVE-2026-60137) — that together achieve remote code execution. The WordPress flaws have received public proof-of-concept exploit code and are being actively chained in the wild.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
DD-WRT (all versions with UPnP exposed)
CRITICAL
PUBLIC
PATCHED
Langflow < 1.9.0
CRITICAL
PUBLIC
PATCHED
WordPress Core 6.9.x (prior to patched release)
CRITICAL
PUBLIC
PATCHED

Apply mitigations per BOD 26-04: disable UPnP on DD-WRT devices or upgrade firmware; upgrade Langflow to v1.9.0 or later; update WordPress Core immediately and remove unused plugins. Federal agencies must remediate per BOD 26-04 Forensics Triage Requirements before the agency-set due date.

For DD-WRT: monitor UPnP ports (TCP/UDP 1900, 5000) for unexpected external connections. For Langflow: alert on anomalous flow_id references in API calls. For WordPress: detect REST API batch-route abuse and unexpected SQL queries in web access logs; monitor for unauthorized admin account creation.

  • https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2021-27137
  • https://nvd.nist.gov/vuln/detail/CVE-2026-0770
  • https://nvd.nist.gov/vuln/detail/CVE-2026-63030
  • https://nvd.nist.gov/vuln/detail/CVE-2026-60137
  • https://github.com/langflow-ai/langflow/releases/tag/v1.9.0
SHARE BRIEF:✕ Post on Xin Share on LinkedIn