【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/20-2026/07/26)

publish date : 2026-07-31 update date : 2026-07-31

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026072808074646 Publication Time 2026-07-28 08:49:47
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-28 08:49:47
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/20-2026/07/26)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000012

【CVE-2026-60137】WordPress Core SQL Injection Vulnerability (CVSS v3.1: 5.9)
【Whether exploited by ransomware: Unknown】WordPress Core contains an SQL Injection vulnerability when a plugin or theme passes untrusted input to the relevant parameter. This vulnerability may be chained with CVE-2026-63030, allowing an unauthenticated attacker to achieve remote code execution in a default WordPress installation environment.

【CVE-2026-63030】WordPress Core Interpretation Conflict Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】WordPress Core contains an Interpretation Conflict vulnerability, which may allow an attacker to perform SQL Injection and achieve remote code execution. This vulnerability may be chained with CVE-2026-60137.

【CVE-2026-0770】Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Langflow contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability, allowing a remote attacker to execute arbitrary code in an affected installation environment.

【CVE-2021-27137】DD-WRT Stack-Based Buffer Overflow Vulnerability (CVSS v3.1: 8.1)
【Whether exploited by ransomware: Unknown】DD-WRT contains a stack-based buffer overflow vulnerability. An unauthenticated attacker may exploit this vulnerability to cause an internal buffer used by UPnP to overflow, thereby triggering a code execution vulnerability.

【CVE-2026-16232】Check Point SmartConsole Improper Authentication Vulnerability (CVSS v3.1: 9.1)
【Whether exploited by ransomware: Unknown】Check Point SmartConsole contains an improper authentication vulnerability. An unauthenticated remote attacker may exploit this vulnerability to obtain an application login token and use it to authenticate with full administrator privileges.

【CVE-2026-50522】Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Microsoft SharePoint contains a deserialization of untrusted data vulnerability. An unauthorized attacker may exploit this vulnerability to execute arbitrary code over a network.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-60137】Please refer to the affected versions listed by the official vendor https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf

【CVE-2026-63030】Please refer to the affected versions listed by the official vendor https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q

【CVE-2026-0770】Langflow version 1.7.3 and earlier

【CVE-2021-27137】DD-WRT versions prior to 45724

【CVE-2026-16232】Please refer to the affected versions listed by the official vendor https://support.checkpoint.com/results/sk/sk185169/

【CVE-2026-50522】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522

[Recommended Actions]

【CVE-2026-60137】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf

【CVE-2026-63030】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q

【CVE-2026-0770】The official vendor has not yet released a corresponding patch. It is recommended to update to another unaffected version https://github.com/langflow-ai/langflow

【CVE-2021-27137】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://svn.dd-wrt.com/changeset/45724

【CVE-2026-16232】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://support.checkpoint.com/results/sk/sk185169/

【CVE-2026-50522】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522

 

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center