CISA's list that day
21 July 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in DD-WRT, Langflow and WordPress Core. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-0770Inclusion of Functionality from Untrusted Control Sphere | Langflow Langflow | Patch nowForensic triage required by CISA; Metasploit module | 0.63 | ||
| CVE-2026-63030Interpretation Conflict | WordPress Core | Patch nowForensic triage required by CISA; Metasploit module | 0.10 | ||
| CVE-2021-27137Stack-Based Buffer Overflow | DD-WRT DD-WRT | Patch nowForensic triage required by CISA | 0.04 | ||
| CVE-2026-60137SQL Injection | WordPress Core | Patch this weekMetasploit module | 0.06 |