CISA flags four flaws under active attack, including two in WordPress

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, its authoritative list of flaws that attackers are actively using in the wild. The additions cover two bugs in WordPress core, a flaw in a popular AI development tool, and a years-old bug in home and small-office router firmware.

What CISA flagged

The four newly listed issues are a SQL injection flaw in WordPress core (CVE-2026-60137), an "interpretation conflict" flaw in WordPress core (CVE-2026-63030), an untrusted-code-inclusion flaw in the Langflow AI application builder (CVE-2026-0770), and a stack-based buffer overflow in DD-WRT router firmware that dates back to 2021 (CVE-2021-27137). A KEV listing is not a routine advisory: CISA adds an entry only when it has concrete evidence that the flaw is already being exploited.

IntelFusions has covered two of these bugs as they surfaced. The WordPress core flaw that lets attackers take over sites without logging in was detailed in our report on the WordPress core takeover, and the Langflow issue featured in our story on attackers hijacking exposed Langflow servers to mine cryptocurrency. CISA's listing confirms that exploitation of both has continued.

Why it matters

WordPress runs a very large share of the world's websites, so two separately exploited core flaws mean a broad population of internet-facing sites is at risk, not just niche plugins. The DD-WRT entry is a reminder that attackers still mine older, unpatched network gear, and the Langflow bug shows exposed AI tooling is now firmly on attackers' target lists.

Under Binding Operational Directive 26-04, U.S. federal civilian agencies must remediate KEV-listed flaws on internet-facing systems on a tight deadline, and the directive now asks agencies to check whether a system was compromised before the patch went on. CISA urges every organization, not just federal agencies, to prioritize these fixes. This mirrors the agency's recent move to flag a SharePoint flaw as actively exploited.

What you should do

Update WordPress core to the latest release rather than relying on plugin-level fixes, upgrade or isolate any exposed Langflow instances, and retire or patch DD-WRT devices running vulnerable firmware. Because CISA has confirmed active exploitation, defenders should also hunt for signs of prior compromise on any system that was exposed while unpatched.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions