CISA Adds Four Known Exploited Vulnerabilities to KEV Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include four new security flaws that are currently being targeted by hackers. Organizations are advised to update their systems immediately to prevent potential attacks.

English Brief
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include four new security flaws that are currently being targeted by hackers. Organizations are advised to update their systems immediately to prevent potential attacks.
الموجز العربي
وكالة الأمن السيبراني الأمريكية تضيف أربع ثغرات مستغلة إلى سجلها الرسمي
قامت وكالة الأمن السيبراني الأمريكية بتحديث قائمة الثغرات المعروفة والمستغلة لتشمل أربع نقاط ضعف أمنية جديدة يتم استهدافها حالياً من قبل المخترقين. يُنصح المؤسسات بتحديث أنظمتها فوراً لتجنب الهجمات المحتملة.
- 1Scan infrastructure for instances of DD-WRT, Langflow, and WordPress.
- 2Verify WordPress version and apply core updates immediately to address CVE-2026-63030 and CVE-2026-60137.
- 3Update DD-WRT firmware to the latest stable release to patch CVE-2021-27137.
English Advisory
// Intelligence Summary
CISA has expanded its Known Exploited Vulnerabilities (KEV) catalog, adding four distinct vulnerabilities identified as being actively exploited in the wild. This action falls under the mandate of BOD 26-04, emphasizing risk-based vulnerability management.
التقرير العربي
// ملخص استخباراتي
قامت وكالة CISA بتوسيع سجل الثغرات المعروفة والمستغلة (KEV) بإضافة أربع ثغرات يتم استغلالها فعلياً حالياً. يأتي هذا الإجراء تماشياً مع التوجيه التشغيلي الملزم رقم 26-04.
// Technical Context
The identified vulnerabilities include:
- CVE-2021-27137: A stack-based buffer overflow affecting DD-WRT.
- CVE-2026-0770: An inclusion of functionality from an untrusted control sphere vulnerability in Langflow.
- CVE-2026-63030: An interpretation conflict vulnerability within WordPress Core.
- CVE-2026-60137: A SQL Injection vulnerability in WordPress Core.
// السياق الفني
الثغرات المضافة تشمل:
- CVE-2021-27137: ثغرة تجاوز سعة المخزن المؤقت في نظام DD-WRT.
- CVE-2026-0770: ثغرة إدراج وظائف من نطاق تحكم غير موثوق في Langflow.
- CVE-2026-63030: ثغرة تضارب التفسير في نواة ووردبريس.
- CVE-2026-60137: ثغرة حقن SQL في نواة ووردبريس.
// Exposure Notes
These vulnerabilities allow various impacts, including potential remote code execution and unauthorized data access. The exploitation of these assets can lead to full system compromise, particularly on internet-facing infrastructure.
// ملاحظات التعرض
تسمح هذه الثغرات بتنفيذ تعليمات برمجية عن بعد أو الوصول غير المصرح به للبيانات، مما قد يؤدي إلى اختراق كامل للأنظمة المتاحة عبر الإنترنت.
// Defensive Priority
Organizations should cross-reference their current software inventory against the KEV catalog. Priority must be given to assets exposed to the internet. Refer to CISA guidance (https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk) for remediation timelines.
// أولوية الدفاع
يجب على المؤسسات مراجعة قوائم البرامج لديهم ومقارنتها بسجل CISA KEV، مع إعطاء الأولوية القصوى للأنظمة المرتبطة بالإنترنت، واتباع التوجيهات المذكورة في موقع (https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk).
Mitigation Checklist
- 1Scan infrastructure for instances of DD-WRT, Langflow, and WordPress.
- 2Verify WordPress version and apply core updates immediately to address CVE-2026-63030 and CVE-2026-60137.
- 3Update DD-WRT firmware to the latest stable release to patch CVE-2021-27137.
- 4Apply patches for Langflow as released by the vendor to remediate CVE-2026-0770.
- 5Check for indicators of compromise (IOCs) prior to applying patches as required by BOD 26-04.
قائمة إجراءات التخفيف
- 1إجراء مسح شامل للبنية التحتية لتحديد إصدارات DD-WRT وLangflow وWordPress.
- 2التأكد من إصدار WordPress وتطبيق التحديثات فوراً لمعالجة CVE-2026-63030 وCVE-2026-60137.
- 3تحديث البرنامج الثابت (Firmware) لـ DD-WRT إلى أحدث إصدار مستقر لمعالجة CVE-2021-27137.
- 4تطبيق التحديثات الأمنية لـ Langflow حسب إصدارات المورد.
- 5التحقق من وجود مؤشرات اختراق (IOCs) قبل تطبيق التحديثات وفقاً لمتطلبات BOD 26-04.
- Source: CISA Alerts
# Remediation Checklist
1. Scan infrastructure for instances of DD-WRT, Langflow, and WordPress.
2. Verify WordPress version and apply core updates immediately to address CVE-2026-63030 and CVE-2026-60137.
3. Update DD-WRT firmware to the latest stable release to patch CVE-2021-27137.
4. Apply patches for Langflow as released by the vendor to remediate CVE-2026-0770.
5. Check for indicators of compromise (IOCs) prior to applying patches as required by BOD 26-04.