CISA's list that day

21 July 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in DD-WRT, Langflow and WordPress Core. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-0770Inclusion of Functionality from Untrusted Control SphereLangflow LangflowPatch nowForensic triage required by CISA; Metasploit module0.63
CVE-2026-63030Interpretation ConflictWordPress CorePatch nowForensic triage required by CISA; Metasploit module0.10
CVE-2021-27137Stack-Based Buffer OverflowDD-WRT DD-WRTPatch nowForensic triage required by CISA0.04
CVE-2026-60137SQL InjectionWordPress CorePatch this weekMetasploit module0.06

Other changes that day

  1. CVE-2026-0257 Palo Alto Networks PAN-OSRansomware use: Unknown to Known.