Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026072808074646 | Publication Time | 2026-07-28 08:49:47 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-07-28 08:49:47 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/20-2026/07/26) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000012 【CVE-2026-60137】WordPress Core SQL Injection Vulnerability (CVSS v3.1: 5.9) 【CVE-2026-63030】WordPress Core Interpretation Conflict Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-0770】Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVSS v3.1: 9.8) 【CVE-2021-27137】DD-WRT Stack-Based Buffer Overflow Vulnerability (CVSS v3.1: 8.1) 【CVE-2026-16232】Check Point SmartConsole Improper Authentication Vulnerability (CVSS v3.1: 9.1) 【CVE-2026-50522】Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8) Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
【CVE-2026-60137】Please refer to the affected versions listed by the official vendor https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf 【CVE-2026-63030】Please refer to the affected versions listed by the official vendor https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q 【CVE-2026-0770】Langflow version 1.7.3 and earlier 【CVE-2021-27137】DD-WRT versions prior to 45724 【CVE-2026-16232】Please refer to the affected versions listed by the official vendor https://support.checkpoint.com/results/sk/sk185169/ 【CVE-2026-50522】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 |
|||
|
[Recommended Actions] 【CVE-2026-60137】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf 【CVE-2026-63030】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q 【CVE-2026-0770】The official vendor has not yet released a corresponding patch. It is recommended to update to another unaffected version https://github.com/langflow-ai/langflow 【CVE-2021-27137】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://svn.dd-wrt.com/changeset/45724 【CVE-2026-16232】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://support.checkpoint.com/results/sk/sk185169/ 【CVE-2026-50522】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
|
|||
|
[Reference] |
|||