Week Ending: July 26, 2026 | Overall Risk Posture: High
CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog during the week ending July 26. The additions affect WordPress, Langflow, DD-WRT, Check Point SmartConsole, and Microsoft SharePoint Server.
The clearest pattern is exposure. Attackers are targeting public websites, AI development tools, routers, security-management software, and collaboration platforms that provide direct paths into valuable environments.
WordPress and SharePoint create the most immediate concern because vulnerable systems may be reachable from the internet. Langflow adds another warning: AI tools are becoming part of the normal enterprise attack surface.
Threat at a Glance
| Area | Key Issue | Defender Priority |
|---|---|---|
| WordPress Core | Two flaws can be chained to compromise vulnerable WordPress websites without authentication. | Upgrade WordPress Core immediately and investigate unexpected administrator accounts, plugins, files, and scheduled activity. |
| Microsoft SharePoint | A deserialization flaw can allow remote code execution against exposed SharePoint Server installations. | Patch every server, search for web shells or altered files, and protect or rotate potentially exposed secrets. |
| Langflow | An exploited vulnerability affects a platform used to build and operate AI workflows. | Upgrade affected deployments and review them for unauthorized files, code execution, or access to connected data stores. |
| Check Point SmartConsole | An authentication weakness affects software used to manage security policy and network controls. | Apply vendor guidance and review administrative sessions, policy changes, and newly created objects. |
| DD-WRT Routers | An older buffer-overflow vulnerability remains useful against vulnerable or forgotten router deployments. | Update supported devices and replace hardware that can no longer receive security fixes. |
Active Exploitation
-
WordPress Core compromise chain
CVE-2026-60137 and CVE-2026-63030 affect WordPress Core. The flaws can be combined to achieve unauthenticated remote code execution against vulnerable installations.
This is especially serious because WordPress is widely deployed and frequently exposed directly to the internet. Once a site is compromised, attackers may install backdoors, create administrator accounts, alter content, redirect visitors, or use the server to reach connected systems. -
Langflow joins the exploited AI attack surface
CVE-2026-0770 affects Langflow, a platform used to build AI applications and workflows.
Langflow systems may connect to language models, databases, API credentials, vector stores, and internal business data. A compromised deployment can therefore expose more than the application itself. Defenders should review connected secrets and downstream services after applying the available fix. -
SharePoint remains under pressure
CVE-2026-50522 is a deserialization vulnerability affecting Microsoft SharePoint Server that can lead to remote code execution.
The addition follows several other exploited SharePoint vulnerabilities added to KEV during July. Organizations should treat vulnerable SharePoint servers as potential breach points and check for persistence instead of stopping after patch installation. -
Check Point management access
CVE-2026-16232 affects Check Point SmartConsole and involves improper authentication.
SmartConsole is used to manage security gateways, policies, network objects, and access rules. Unauthorized access to the management layer could allow an attacker to weaken controls or create pathways that appear legitimate to other security systems. -
Old routers remain exploitable
CVE-2021-27137 is a stack-based buffer-overflow vulnerability affecting DD-WRT.
Its inclusion is another reminder that attackers continue to use older vulnerabilities when outdated routers remain reachable. Devices outside normal asset inventories are particularly likely to miss patches, monitoring, and replacement cycles.
What Connects the Week
-
Public-facing software remains the fastest route in
WordPress and SharePoint often sit directly on the internet. Attackers can scan broadly and move quickly once exploit details become available. -
Management systems increase the blast radius
SmartConsole and routers do more than host data. They control access, traffic, and security policy, making their compromise more valuable than an ordinary endpoint. -
AI tools inherit traditional software risks
Langflow may support modern AI workflows, but it still depends on web services, permissions, credentials, and connected infrastructure. AI branding does not remove standard application-security problems. -
Old and new vulnerabilities coexist
The week includes recent flaws alongside a DD-WRT vulnerability from 2021. Attackers use whatever remains exposed, regardless of age.
Defender Priorities
-
Patch WordPress and SharePoint first
Prioritize internet-facing installations. Confirm versions across every server and do not assume automatic updates completed successfully. -
Investigate before closing the ticket
Search for new accounts, unknown plugins, web shells, modified files, scheduled tasks, unusual login activity, and outbound connections. -
Review AI-platform credentials
Identify secrets available to Langflow, including model keys, database credentials, cloud tokens, and connections to internal applications. -
Audit security-management changes
Review SmartConsole administrator activity, policy edits, newly created objects, rule changes, and unexpected gateway configuration updates. -
Find forgotten routers
Include branch offices, labs, temporary sites, home-office equipment, and inherited infrastructure in the router inventory. Replace unsupported devices.
Weekly Pulse
This week’s six KEV additions show attackers moving across five different layers: websites, collaboration platforms, AI tooling, security management, and network infrastructure.
WordPress and SharePoint represent the most urgent exposure because exploitation can begin from the public internet. Langflow deserves special attention because compromised AI tools may provide access to credentials and connected data sources.
The practical lesson is simple: inventory what is exposed, patch what is actively exploited, and investigate systems that may have been vulnerable before the fix was applied.
Bottom Line
CISA added six actively exploited vulnerabilities this week across WordPress, Langflow, DD-WRT, Check Point SmartConsole, and Microsoft SharePoint.
Defenders should patch public-facing WordPress and SharePoint systems first, then review Langflow credentials, SmartConsole activity, and unsupported router deployments.
Websites, AI workflows, security consoles, and routers are separate technologies—but to an attacker, they are all possible doors into the same organization.
Sources
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — Four KEV Additions, July 21, 2026
- CISA — Two KEV Additions, July 22, 2026
- WordPress — Security Releases
- Microsoft — CVE-2026-50522
- NVD — CVE-2026-60137 WordPress
- NVD — CVE-2026-63030 WordPress
- NVD — CVE-2026-0770 Langflow
- NVD — CVE-2026-16232 Check Point SmartConsole
- NVD — CVE-2021-27137 DD-WRT

