logo

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog

ID: be514d83-31d9-52b0-b0f8-1efc668f4150

STIX ID: report--be514d83-31d9-52b0-b0f8-1efc668f4150

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Pierluigi Paganini

...
...

CISA added multiple high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog — a DD-WRT UPnP buffer overflow, a critical Langflow RCE via untrusted functionality loading, and two WordPress Core flaws (a REST API route confusion and an SQL injection) that can be chained for pre-auth remote code execution; public PoCs exist for the WordPress issues and federal agencies have mandated patch deadlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.