● Daily security briefing
Tuesday, July 21, 2026
Today's security advisory activity included the addition of four new Known Exploited Vulnerabilities (KEVs), notably CVE-2026-60137 and CVE-2026-63030, both affecting WordPress Core, as well as CVE-2021-27137 related to DD-WRT and CVE-2026-0770 concerning Langflow. The most critical advisories released today include Microsoft's July 2026 monthly rollup and a Siemens CADRA advisory, both marked as critical and exploited. Additionally, CISA has added four vulnerabilities to its catalog, highlighting ongoing threats. Among notable CVEs, several critical vulnerabilities were published, including CVE-2026-65008 in Grav and CVE-2026-13439 affecting a WordPress plugin, both posing significant risks. Overall, while CERT/PSIRT output was quiet, the volume of notable CVEs underscores the need for vigilance.
14 critical7 high3 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2026-60137CVE-2026-60137: WordPress Core SQL Injection Vulnerability
- exploitedCVE-2021-27137CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability
- exploitedCVE-2026-63030CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability
- exploitedCVE-2026-0770CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- criticalexploitedcccsMicrosoft security advisory – July 2026 monthly rollup (AV26-698) – Update 2
- highexploitedcisaCISA Adds Four Known Exploited Vulnerabilities to Catalog
- unknownexploitedcisco-psirtCisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
- criticalexploitedcisaSiemens CADRA
- unknownexploitedcccsWordPress security advisory (AV26-723) - Update 1
- unknownexploitedncsc-nlNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Office
- highcert-bund[UPDATE] [high] Evince: Vulnerability allows code execution
- highcert-bund[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities enable denial of service
- highcert-bund[NEW] [high] rsyslog: Vulnerability allows Denial of Service and potentially code execution
- highcert-bund[NEW] [high] Synacor Zimbra: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (sssd, glib, c-ares): Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-20896CVSS 9.8GHSA-f75j-4cw6-rmx4: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
- criticalCVE-2026-65008CVSS 9.8Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method cal
- criticalCVE-2026-64606CVSS 9.8Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected
- criticalCVE-2026-1617CVSS 9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injec
- criticalCVE-2026-64608CVSS 9.8Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate t
- criticalCVE-2026-13439CVSS 9.8The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is du
- criticalCVE-2026-59891CVSS 9.6GHSA-pf56-329r-95rw: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
- criticalCVE-2026-58426CVSS 9.6GHSA-hg5r-vq93-9fv6: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
- criticalCVE-2026-65007CVSS 9.6The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks
- criticalCVE-2026-22874CVSS 9.6GHSA-2r5c-gw76-rh3w: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
- criticalCVE-2026-58443CVSS 9.6GHSA-xxjv-752h-3vp2: Gitea: Public-only repository tokens can update private PR head branches
- criticalCVSS 9.4GHSA-p63j-vcc4-9vmv: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 279 above.