CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Tuesday, July 21, 2026

Today's security advisory activity included the addition of four new Known Exploited Vulnerabilities (KEVs), notably CVE-2026-60137 and CVE-2026-63030, both affecting WordPress Core, as well as CVE-2021-27137 related to DD-WRT and CVE-2026-0770 concerning Langflow. The most critical advisories released today include Microsoft's July 2026 monthly rollup and a Siemens CADRA advisory, both marked as critical and exploited. Additionally, CISA has added four vulnerabilities to its catalog, highlighting ongoing threats. Among notable CVEs, several critical vulnerabilities were published, including CVE-2026-65008 in Grav and CVE-2026-13439 affecting a WordPress plugin, both posing significant risks. Overall, while CERT/PSIRT output was quiet, the volume of notable CVEs underscores the need for vigilance.

Last updated 03:46 UTC

CERT / PSIRT advisories
279
CVEs published
5408
Added to KEV
4
Known exploited
6

14 critical7 high3 unknownacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Highest exploitation probability

EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 279 above.

plus 231 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.