This month: 21 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2021-27137
DD-WRT · DD-WRT
DD-WRT Stack-Based Buffer Overflow Vulnerability
Detected Jul 21 · 3-day patch deadline
CVE-2026-0770
Langflow · Langflow
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Detected Jul 21 · 3-day patch deadline
CVE-2026-63030
WordPress · Core
WordPress Core Interpretation Conflict Vulnerability
Detected Jul 21 · 3-day patch deadline

KEV Intelligence Brief — July 21, 2026

Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: TLP:CLEAR | Distribution: Unlimited

Eight vulnerabilities added to CISA's KEV catalog across the past week demand immediate attention. Three thematic clusters emerge: a pair of chained WordPress flaws reshaping web infrastructure risk, a wave of unauthenticated RCE across enterprise and network tooling, and a low-profile OT/building automation vulnerability with outsized physical consequences. Several deadlines have already passed — teams should treat any gap as an active incident posture, not a compliance lag.

Deadline Passed: Fortinet, SharePoint, and the Cost of Delay

Three entries carry patch deadlines of July 19, 2026 — two days ago. If your organization has not already acted, treat these systems as potentially compromised and initiate forensic triage per CISA's BOD 26-04 Forensics Triage Requirements before applying patches.

CVE-2026-25089 and CVE-2026-39808 both affect Fortinet FortiSandbox — including its cloud and PaaS variants — and both enable unauthenticated OS command injection via crafted HTTP requests. These are not theoretical: unauthenticated command injection against a security appliance is a high-confidence attacker target because FortiSandbox sits in privileged network positions, often with visibility into detonation environments and threat telemetry. The irony is not lost that a sandbox product is the attack surface here. Organizations should verify that FortiSandbox management interfaces are not internet-exposed, segment them behind jump hosts, and rotate any service account credentials that the appliance uses for upstream integrations — even after patching. Consult Fortinet's PSIRT advisory at fortiguard.fortinet.com/psirt for version-specific guidance.

CVE-2026-58644 affects Microsoft SharePoint and allows unauthenticated network-based code execution through deserialization of untrusted data — a class of vulnerability that is reliably weaponizable and has a long history in SharePoint's threat landscape. On-premises SharePoint deployments are the primary concern; Microsoft 365-hosted tenants should verify with Microsoft's service health dashboard that mitigations are applied at the platform layer. For self-hosted deployments, block external access to /_layouts/ and SharePoint API endpoints at the perimeter immediately if patching cannot be completed retroactively, and review authentication logs for anomalous service account activity going back at least 30 days.

Chained and Dangerous: WordPress Core Exploitation at Scale

CISA's simultaneous addition of CVE-2026-60137 and CVE-2026-63030 — both affecting WordPress Core — is a deliberate signal. These two vulnerabilities are explicitly documented as a chain: CVE-2026-60137 introduces a SQL injection condition when plugins or themes pass untrusted input to a vulnerable parameter, while CVE-2026-63030 represents an interpretation conflict that completes the chain, enabling an unauthenticated attacker to achieve remote code execution on default WordPress installations.

That last phrase deserves emphasis. This is not a misconfiguration problem or a third-party plugin issue in isolation — default WordPress deployments are in scope. Given that WordPress powers an estimated 40% of public web infrastructure, the blast radius of active exploitation is significant. CVE-2026-63030 carries the tighter deadline of July 24; CVE-2026-60137 extends to August 4, but treating them as separate remediation events is operationally dangerous given their interdependence.

DevOps teams managing WordPress at scale should prioritize core updates immediately, audit any plugin or theme that passes user-controlled input to database query parameters, and implement a web application firewall rule set targeting SQL injection payloads as a compensating control while updates propagate. Federal contractors hosting public-facing WordPress sites must ensure BOD 26-04 compliance for the July 24 deadline or document an approved exception with compensating controls in place.

Infrastructure Perimeter and OT: Router Flaws and Building System Lockouts

CVE-2021-27137 in DD-WRT is a 2021 CVE reaching the KEV catalog in 2026 — which tells you exploitation is still occurring in the wild at meaningful volume. The vulnerability is a stack-based buffer overflow in the UPnP service, exploitable by unauthenticated attackers for code execution. DD-WRT remains widely deployed on small office, home office, and branch network hardware, often with UPnP enabled by default and management interfaces inadvertently exposed. The patch deadline is July 24. Where firmware updates are unavailable for end-of-life hardware, the required action is clear: disable UPnP, restrict management interface access to trusted internal subnets, or replace the device. This is not a router most enterprises track in their asset inventories — which is precisely why it matters.

CVE-2023-4346 affecting KNX Association's KNX Protocol Connection Authorization Option 1 is the entry most likely to be overlooked by IT-focused teams — and the most consequential if missed in OT and facilities environments. This vulnerability enables an attacker to exploit an overly restrictive account lockout mechanism to purge all devices on a KNX bus and set a BCU key, effectively bricking or locking building automation infrastructure: HVAC, lighting, access control, and safety systems. The patch deadline is July 29. Facilities teams, building management system integrators, and physical security stakeholders must be looped in immediately. Compensating controls include network isolation of KNX IP interfaces, disabling remote access to KNX bus segments, and enabling higher-security authorization tiers where the device supports them.

CVE-2026-0770 in Langflow — an increasingly common AI workflow orchestration platform — allows remote attackers to execute arbitrary code by loading functionality from an untrusted control sphere. Langflow deployments have proliferated rapidly in AI development pipelines, often standing up quickly without the same security scrutiny as production infrastructure. The deadline is July 24. Teams should audit all Langflow instances for internet exposure, enforce authentication at the reverse proxy layer, and evaluate whether any instance handles sensitive data or has downstream integrations that could be pivoted from.

Summary Deadline Matrix

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-25089 | Fortinet FortiSandbox | July 19 | OVERDUE | | CVE-2026-39808 | Fortinet FortiSandbox | July 19 | OVERDUE | | CVE-2026-58644 | Microsoft SharePoint | July 19 | OVERDUE | | CVE-2021-27137 | DD-WRT | July 24 | 3 days | | CVE-2026-0770 | Langflow | July 24 | 3 days | | CVE-2026-63030 | WordPress Core | July 24 | 3 days | | CVE-2023-4346 | KNX Protocol | July 29 | 8 days | | CVE-2026-60137 | WordPress Core | August 4 | 14 days |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Fortinet PSIRT Advisories · Microsoft Security Response Center · WordPress Security Releases · KNX Association Security · CISA ICS Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — July 21, 2026

South Korea Investigates Breach of Diplomatic Database, North Korea Attribution Examined

South Korean authorities are investigating a breach of a government-run diplomatic academy database containing approximately 10,000 records of current and retired diplomats. The compromised system held sensitive information on nearly the country's entire diplomatic corps. Officials are examining potential involvement by foreign state-backed hacking groups, with early focus on possible North Korean threat actors, though no attribution has been confirmed. The breach represents a significant intelligence collection opportunity for adversaries targeting South Korean foreign policy operations and personnel.

Microsoft Patches Record 570 Vulnerabilities Including Three Zero-Days

Microsoft's July 2026 Patch Tuesday addresses 570 security flaws, marking a record volume for the company. Three zero-day vulnerabilities are included: CVE-2026-56155, an Active Directory Federation Services elevation of privilege flaw being actively exploited to gain administrator privileges, and two additional zero-days—one actively exploited and one publicly disclosed. Separately, Ukraine's CERT-UA issued warnings about Russian operators deploying fake CAPTCHA checks that trick users into executing malicious commands on their own systems. Russian FSB Center 16 operators continue targeting critical infrastructure through exploitation of misconfigured routers and vulnerable networking devices. In the cryptocurrency sector, extortion groups ShinyHunters and ShadowByt3$ claim to have exfiltrated patient data from healthcare giant Abbott, though the company has not confirmed the extent of the incidents under investigation.

Sources: Bloomberg · Reuters · Bleeping Computer · Malwarebytes · Bitdefender · JD Supra · Malwarebytes

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.bleepingcomputer.comJul 20

New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the Nightmare Eclipse handle released a Windows zero-day exploit called LegacyHive that allows attackers to escalate privi...

https://cybersecuritynews.comJul 20

Hugging Face Attacked by Autonomous AI Agent — GhostCommit and Other AI Attack Vectors Disclosed

Multiple AI-integrated systems became attack surfaces this week, including Hugging Face breach by autonomous AI agent and novel security threats like ...

https://www.thestack.technologyJul 20

Hugging Face hacked: Turned to Chinese LLM for help after US models blocked Blue Team

The platform's security team were initially stymied in their incident response (IR) by unnamed US LLM frontier model guardrails “which cannot ...

https://abcnews.comJul 19

Fairlife pauses US production after cyberattack breached milk brand's systems - ABC News

Ransomware attacks — in which hackers demand a hefty payment to restore hacked systems — also account for a growing share of cyber crimes. And ...

https://www.cnbc.comJul 19

Cybersecurity risks posed by over-the-air tech in autos has analysts concerned - CNBC

The automotive industry's increasing use of over-the-air technology makes it more susceptible to cyberattacks, analysts say.

https://abc7chicago.comJul 18

Chicago-based Fairlife pauses US production after ransomware cyberattack breaches milk ...

Chicago-based Fairlife has paused US production after a ransomware cyberattack breached the milk brand's systems. They're owned by Coca-Cola.

https://www.cybersecuritydive.comJul 18

Abbott discloses cyberattack on cancer diagnostics business - Cybersecurity Dive

The cyberattack follows Abbott's recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.

https://www.securityweek.comMay 19

China-Linked APT Expands Arsenal With New 'Leash' Backdoors

Chinese APT group UAT-7810 has expanded its espionage infrastructure arsenal with new backdoors including LongLeash, DogleAsh, and JarLeash tools targ...


Updated daily