CISA Adds Four Known Exploited Vulnerabilities to KEV Catalog

CISA adds four actively exploited vulnerabilities to its KEV catalog. Learn about the CVEs and urgent patching requirements under BOD 26-04.

miércoles, 22 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Nuevas CVEs en el catálogo de explotación conocida de CISA

The cybersecurity landscape remains on constant alert. Recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This decision is based on evidence of active exploitation by malicious actors, underscoring the urgency of addressing these security flaws. The vulnerabilities affect widely used technologies: a stack-based buffer overflow in DD-WRT firmware, an inclusion of functionality from an untrusted control sphere issue in Langflow, and two core WordPress flaws: an interpretation conflict and an SQL injection. These incidents not only pose a significant risk to federal agencies but also to any organization relying on these technologies.

CISA, following the Binding Operational Directive (BOD) 26-04, requires Federal Civilian Executive Branch (FCEB) agencies to prioritize remediation of these critical vulnerabilities. However, the impact extends beyond government. Businesses of all sizes must adopt a risk-based vulnerability management approach, as recommended by the agency. The inclusion of new CVEs in the KEV catalog is a reminder that attackers never rest and exploit any available weak point, especially those granting full control of the compromised system.

Let us analyze each vulnerability in detail. The first, CVE-2021-27137, is a stack-based buffer overflow in DD-WRT, an open-source firmware very popular for routers and access points. This vulnerability allows a remote attacker to execute arbitrary code, taking control of the network device. Since routers are the gateway to corporate networks, successful exploitation can compromise the entire infrastructure. The second, CVE-2026-0770, affects Langflow, an open-source platform for building artificial intelligence applications based on workflows. The flaw allows inclusion of functionality from untrusted sources, which could lead to malicious code execution in AI environments. This is especially concerning at a time when the adoption of AI agents and language models is growing exponentially. The remaining two vulnerabilities, CVE-2026-63030 and CVE-2026-60137, directly target WordPress, the world's most widely used content management system. The first is an interpretation conflict that can be exploited to bypass security controls, while the second is an SQL injection allowing access, modification, or deletion of data in the underlying database. Both pose a direct threat to the integrity of websites and user data.

Directive BOD 26-04 not only sets patching priorities but also requires agencies to verify if systems were compromised before applying the update. This compromise assessment process requires advanced monitoring and incident response capabilities. For private companies, although the directive is not mandatory, adopting these practices is a strategic decision. Proactive vulnerability management, combined with cybersecurity services such as those offered by Q2BSTUDIO, allows detection and mitigation of threats before they materialize. At Q2BSTUDIO we offer cybersecurity and pentesting services that help identify these critical flaws in cloud infrastructures, web applications, and legacy systems.

The rapid evolution of threats demands a comprehensive approach. Organizations cannot afford to ignore these vulnerabilities. Implementing a continuous update program and adopting secure architectures are fundamental steps. This is where custom software development and cloud solutions come into play. Q2BSTUDIO, as a software development and technology company, supports its clients in creating custom applications that incorporate security by design. Additionally, our services in AWS and Azure cloud ensure scalable and secure environments with constant monitoring and automatic updates. The integration of artificial intelligence, such as AI agents for anomaly detection, enables immediate response to suspicious behavior.

It is crucial to understand that cybersecurity is not a destination but a continuous process. Each new vulnerability cataloged by CISA is a lesson. Businesses must assess their exposure and prioritize remediation according to their business context. For example, those relying on WordPress sites should immediately patch CVE-2026-63030 and CVE-2026-60137, while those using DD-WRT routers need to update the firmware. Likewise, AI teams using Langflow must review their configurations to avoid inclusion of malicious code.

CISA's KEV catalog is an invaluable tool for security teams. CISA invites anyone to nominate exploited vulnerabilities not yet listed, as long as they have a CVE ID, evidence of exploitation, and clear mitigation guidance. This collective effort strengthens global defense. But the ultimate responsibility lies with each organization. Investing in cybersecurity is no longer optional; it is a strategic necessity.

Q2BSTUDIO understands this reality. That is why we offer comprehensive solutions ranging from security consulting to robust software development, including process automation with AI agents and data analysis with Power BI. For example, a Business Intelligence dashboard can monitor in real time the status of vulnerabilities in the cloud infrastructure, alerting on critical CVEs. The combination of cloud services in AWS and Azure with advanced security practices ensures that applications are protected from the start.

In conclusion, the addition of these four vulnerabilities to the KEV catalog is a wake-up call. Organizations must act quickly, adopting a risk-based approach and relying on trusted technology partners. Q2BSTUDIO is ready to help companies of all sizes navigate this complex landscape, offering cybersecurity, cloud, AI, and custom software development solutions that not only mitigate risks but also drive innovation. Do not wait to become a victim of an attack: review your systems, update your tools, and contact us to strengthen your security posture.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.