CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — July 21, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: TLP:CLEAR | Distribution: Unlimited
Eight vulnerabilities added to CISA's KEV catalog across the past week demand immediate attention. Three thematic clusters emerge: a pair of chained WordPress flaws reshaping web infrastructure risk, a wave of unauthenticated RCE across enterprise and network tooling, and a low-profile OT/building automation vulnerability with outsized physical consequences. Several deadlines have already passed — teams should treat any gap as an active incident posture, not a compliance lag.
Deadline Passed: Fortinet, SharePoint, and the Cost of Delay
Three entries carry patch deadlines of July 19, 2026 — two days ago. If your organization has not already acted, treat these systems as potentially compromised and initiate forensic triage per CISA's BOD 26-04 Forensics Triage Requirements before applying patches.
CVE-2026-25089 and CVE-2026-39808 both affect Fortinet FortiSandbox — including its cloud and PaaS variants — and both enable unauthenticated OS command injection via crafted HTTP requests. These are not theoretical: unauthenticated command injection against a security appliance is a high-confidence attacker target because FortiSandbox sits in privileged network positions, often with visibility into detonation environments and threat telemetry. The irony is not lost that a sandbox product is the attack surface here. Organizations should verify that FortiSandbox management interfaces are not internet-exposed, segment them behind jump hosts, and rotate any service account credentials that the appliance uses for upstream integrations — even after patching. Consult Fortinet's PSIRT advisory at fortiguard.fortinet.com/psirt for version-specific guidance.
CVE-2026-58644 affects Microsoft SharePoint and allows unauthenticated network-based code execution through deserialization of untrusted data — a class of vulnerability that is reliably weaponizable and has a long history in SharePoint's threat landscape. On-premises SharePoint deployments are the primary concern; Microsoft 365-hosted tenants should verify with Microsoft's service health dashboard that mitigations are applied at the platform layer. For self-hosted deployments, block external access to /_layouts/ and SharePoint API endpoints at the perimeter immediately if patching cannot be completed retroactively, and review authentication logs for anomalous service account activity going back at least 30 days.
Chained and Dangerous: WordPress Core Exploitation at Scale
CISA's simultaneous addition of CVE-2026-60137 and CVE-2026-63030 — both affecting WordPress Core — is a deliberate signal. These two vulnerabilities are explicitly documented as a chain: CVE-2026-60137 introduces a SQL injection condition when plugins or themes pass untrusted input to a vulnerable parameter, while CVE-2026-63030 represents an interpretation conflict that completes the chain, enabling an unauthenticated attacker to achieve remote code execution on default WordPress installations.
That last phrase deserves emphasis. This is not a misconfiguration problem or a third-party plugin issue in isolation — default WordPress deployments are in scope. Given that WordPress powers an estimated 40% of public web infrastructure, the blast radius of active exploitation is significant. CVE-2026-63030 carries the tighter deadline of July 24; CVE-2026-60137 extends to August 4, but treating them as separate remediation events is operationally dangerous given their interdependence.
DevOps teams managing WordPress at scale should prioritize core updates immediately, audit any plugin or theme that passes user-controlled input to database query parameters, and implement a web application firewall rule set targeting SQL injection payloads as a compensating control while updates propagate. Federal contractors hosting public-facing WordPress sites must ensure BOD 26-04 compliance for the July 24 deadline or document an approved exception with compensating controls in place.
Infrastructure Perimeter and OT: Router Flaws and Building System Lockouts
CVE-2021-27137 in DD-WRT is a 2021 CVE reaching the KEV catalog in 2026 — which tells you exploitation is still occurring in the wild at meaningful volume. The vulnerability is a stack-based buffer overflow in the UPnP service, exploitable by unauthenticated attackers for code execution. DD-WRT remains widely deployed on small office, home office, and branch network hardware, often with UPnP enabled by default and management interfaces inadvertently exposed. The patch deadline is July 24. Where firmware updates are unavailable for end-of-life hardware, the required action is clear: disable UPnP, restrict management interface access to trusted internal subnets, or replace the device. This is not a router most enterprises track in their asset inventories — which is precisely why it matters.
CVE-2023-4346 affecting KNX Association's KNX Protocol Connection Authorization Option 1 is the entry most likely to be overlooked by IT-focused teams — and the most consequential if missed in OT and facilities environments. This vulnerability enables an attacker to exploit an overly restrictive account lockout mechanism to purge all devices on a KNX bus and set a BCU key, effectively bricking or locking building automation infrastructure: HVAC, lighting, access control, and safety systems. The patch deadline is July 29. Facilities teams, building management system integrators, and physical security stakeholders must be looped in immediately. Compensating controls include network isolation of KNX IP interfaces, disabling remote access to KNX bus segments, and enabling higher-security authorization tiers where the device supports them.
CVE-2026-0770 in Langflow — an increasingly common AI workflow orchestration platform — allows remote attackers to execute arbitrary code by loading functionality from an untrusted control sphere. Langflow deployments have proliferated rapidly in AI development pipelines, often standing up quickly without the same security scrutiny as production infrastructure. The deadline is July 24. Teams should audit all Langflow instances for internet exposure, enforce authentication at the reverse proxy layer, and evaluate whether any instance handles sensitive data or has downstream integrations that could be pivoted from.
Summary Deadline Matrix
| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-25089 | Fortinet FortiSandbox | July 19 | OVERDUE | | CVE-2026-39808 | Fortinet FortiSandbox | July 19 | OVERDUE | | CVE-2026-58644 | Microsoft SharePoint | July 19 | OVERDUE | | CVE-2021-27137 | DD-WRT | July 24 | 3 days | | CVE-2026-0770 | Langflow | July 24 | 3 days | | CVE-2026-63030 | WordPress Core | July 24 | 3 days | | CVE-2023-4346 | KNX Protocol | July 29 | 8 days | | CVE-2026-60137 | WordPress Core | August 4 | 14 days |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Fortinet PSIRT Advisories · Microsoft Security Response Center · WordPress Security Releases · KNX Association Security · CISA ICS Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — July 21, 2026
South Korea Investigates Breach of Diplomatic Database, North Korea Attribution Examined
South Korean authorities are investigating a breach of a government-run diplomatic academy database containing approximately 10,000 records of current and retired diplomats. The compromised system held sensitive information on nearly the country's entire diplomatic corps. Officials are examining potential involvement by foreign state-backed hacking groups, with early focus on possible North Korean threat actors, though no attribution has been confirmed. The breach represents a significant intelligence collection opportunity for adversaries targeting South Korean foreign policy operations and personnel.
Microsoft Patches Record 570 Vulnerabilities Including Three Zero-Days
Microsoft's July 2026 Patch Tuesday addresses 570 security flaws, marking a record volume for the company. Three zero-day vulnerabilities are included: CVE-2026-56155, an Active Directory Federation Services elevation of privilege flaw being actively exploited to gain administrator privileges, and two additional zero-days—one actively exploited and one publicly disclosed. Separately, Ukraine's CERT-UA issued warnings about Russian operators deploying fake CAPTCHA checks that trick users into executing malicious commands on their own systems. Russian FSB Center 16 operators continue targeting critical infrastructure through exploitation of misconfigured routers and vulnerable networking devices. In the cryptocurrency sector, extortion groups ShinyHunters and ShadowByt3$ claim to have exfiltrated patient data from healthcare giant Abbott, though the company has not confirmed the extent of the incidents under investigation.
Sources: Bloomberg · Reuters · Bleeping Computer · Malwarebytes · Bitdefender · JD Supra · Malwarebytes
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the Nightmare Eclipse handle released a Windows zero-day exploit called LegacyHive that allows attackers to escalate privi...
Hugging Face Attacked by Autonomous AI Agent — GhostCommit and Other AI Attack Vectors Disclosed
Multiple AI-integrated systems became attack surfaces this week, including Hugging Face breach by autonomous AI agent and novel security threats like ...
Hugging Face hacked: Turned to Chinese LLM for help after US models blocked Blue Team
The platform's security team were initially stymied in their incident response (IR) by unnamed US LLM frontier model guardrails “which cannot ...
Fairlife pauses US production after cyberattack breached milk brand's systems - ABC News
Ransomware attacks — in which hackers demand a hefty payment to restore hacked systems — also account for a growing share of cyber crimes. And ...
Cybersecurity risks posed by over-the-air tech in autos has analysts concerned - CNBC
The automotive industry's increasing use of over-the-air technology makes it more susceptible to cyberattacks, analysts say.
Chicago-based Fairlife pauses US production after ransomware cyberattack breaches milk ...
Chicago-based Fairlife has paused US production after a ransomware cyberattack breached the milk brand's systems. They're owned by Coca-Cola.
Abbott discloses cyberattack on cancer diagnostics business - Cybersecurity Dive
The cyberattack follows Abbott's recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.
China-Linked APT Expands Arsenal With New 'Leash' Backdoors
Chinese APT group UAT-7810 has expanded its espionage infrastructure arsenal with new backdoors including LongLeash, DogleAsh, and JarLeash tools targ...
Updated daily
