CISA adds six vulnerabilities to KEV – July 2026

CISA adds six vulnerabilities to KEV – July 2026


On 21 and 22 July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding six vulnerabilities spanning enterprise collaboration platforms, AI frameworks, network infrastructure, and the world’s most widely used content management system. While KEV additions occur regularly, the diversity and concentration of these vulnerabilities over a 48-hour period highlight an important trend: attackers are increasingly targeting technologies that organizations inherently trust and expose to the internet.

The six additions are not random. Together, they reflect the modern attacker’s playbook—targeting management interfaces, AI applications, collaboration platforms, web applications, and edge devices to maximize operational impact.

CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow

This vulnerability affects DD-WRT, an open-source firmware used by routers and network appliances. Although the CVE dates back to 2021, its addition to the KEV Catalog in July 2026 confirms that attackers continue to exploit unpatched legacy systems.

Routers often remain outside the visibility of traditional vulnerability management programs because they are managed separately from servers and endpoints. Once compromised, these edge devices can provide persistent access, traffic visibility, and a launch point for lateral movement.

Security takeaway: Network appliances should receive the same patching priority and continuous monitoring as critical servers and endpoints.

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere

The inclusion of Langflow in the KEV Catalog is a significant milestone because it highlights that AI platforms are now part of the enterprise attack surface.

This vulnerability can allow attackers to abuse untrusted functionality, potentially leading to remote code execution. Organizations deploying AI-powered applications should treat AI frameworks with the same rigor as traditional enterprise software.

Security teams should ensure AI platforms are included in:

  • Asset inventories
  • Vulnerability management
  • Secure configuration baselines
  • Continuous monitoring
  • Patch management

AI is no longer experimental—it is operational infrastructure.

CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability

This vulnerability affects the WordPress Core software and may allow attackers to achieve remote code execution under specific conditions.

Because WordPress powers a substantial portion of the public internet, exploitation opportunities span government agencies, enterprises, educational institutions, and small businesses.

Internet-facing WordPress installations should be reviewed immediately to ensure patches have been applied and unnecessary plugins or custom code are not introducing additional risk.

CVE-2026-60137: WordPress Core SQL Injection Vulnerability

The second WordPress Core vulnerability added to the KEV Catalog is a SQL Injection flaw.

SQL Injection continues to be one of the most effective attack techniques because it can expose sensitive information, bypass authentication, manipulate application data, and provide a foothold for further compromise.

The addition of two WordPress Core vulnerabilities within a single KEV update demonstrates that web applications remain one of the most actively targeted attack surfaces.

CVE-2026-16232: Check Point SmartConsole Improper Authentication

This vulnerability affects Check Point SmartConsole, an administrative platform used to manage enterprise security infrastructure.

Administrative consoles have always been attractive targets because compromising them can provide direct control over security policies, devices, and privileged configurations.

Organizations should ensure management interfaces are protected through strong authentication, network segmentation, least privilege, and continuous monitoring.

CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data

This vulnerability affects Microsoft SharePoint and can enable remote code execution through unsafe deserialization.

SharePoint remains deeply embedded within enterprise collaboration environments, making it an attractive target for threat actors seeking access to sensitive business data and privileged environments.

Historically, SharePoint vulnerabilities have been leveraged extensively during large-scale intrusion campaigns, reinforcing the need for rapid patch deployment and proactive threat hunting.

Final Thoughts

The six KEV additions announced across 21–22 July 2026 are more than routine vulnerability updates. They represent a clear signal that attackers are focusing on technologies organizations trust the most—from AI frameworks and collaboration platforms to network appliances and web applications.

A mature vulnerability management program is no longer defined by the number of patches deployed. It is defined by how quickly an organization can identify, prioritize, and remediate vulnerabilities that are already being exploited in the wild.

Known Exploited Vulnerabilities are not theoretical risks—they are active business risks demanding immediate action.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.