THREAT SUMMARY
Category: Active Exploitation / Network Infrastructure / Artificial Intelligence Platforms / Content Management Systems / Web Application Security
Affected Products: DD-WRT, Langflow, WordPress Core
CVEs: CVE-2021-27137, CVE-2026-0770, CVE-2026-63030, CVE-2026-60137
Primary Risks: Stack-Based Buffer Overflow, Unauthenticated Remote Code Execution, Router Compromise, SQL Injection, Database Exposure, Administrative Account Creation, Website Takeover, Malware Deployment, Credential and Secret Theft
Threat Status: Confirmed Active Exploitation
Affected Environment: Federal Agencies, Enterprise Networks, Critical Infrastructure, Organizations Operating DD-WRT Routers, Langflow Platforms, and WordPress Websites
Attack Vectors: Crafted UPnP Requests, Untrusted Functionality Inclusion, Malicious Requests to Langflow Validation Functions, REST API Batch-Route Confusion, SQL Injection
CISA Action: Added to Known Exploited Vulnerabilities (KEV) Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities affecting DD-WRT, Langflow, and WordPress Core to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation.
The newly added vulnerabilities affect network routers, artificial intelligence development infrastructure, and one of the world’s most widely deployed content management systems. Successful exploitation could allow attackers to compromise network devices, execute unauthorized code, access databases, create administrative accounts, deploy web shells, steal credentials, manipulate websites, or establish long-term persistence.
The addition of these vulnerabilities to the KEV Catalog confirms that they have moved beyond theoretical risk and are being used against operational systems. Organizations operating affected products should treat remediation and compromise assessment as immediate security priorities.
Vulnerability Details
CVE-2021-27137 — DD-WRT
Vulnerability: Stack-Based Buffer Overflow
CVE-2021-27137 is a stack-based buffer overflow vulnerability affecting the Universal Plug and Play service in DD-WRT router firmware.
The vulnerability exists in the processing of Simple Service Discovery Protocol requests. An unauthenticated attacker can send a specially crafted M-SEARCH request containing oversized data that exceeds the capacity of a fixed internal buffer.
Successful exploitation could corrupt memory and allow an attacker to execute unauthorized code on the affected router. Compromised routers can be used to redirect traffic, modify network settings, deploy malware, conduct distributed denial-of-service attacks, scan connected systems, or provide attackers with persistent access to internal networks.
The vulnerability affects DD-WRT versions before build 45724. Exploitation requires UPnP to be enabled. Although UPnP is disabled by default and generally restricted to internal interfaces, exposed or improperly configured devices can remain vulnerable.
Routers occupy a critical position between internal systems and external networks. A compromised router can provide attackers with access to network traffic, administrative functions, connected devices, and trusted communications that may not receive the same scrutiny as activity originating directly from the internet.
CVE-2026-0770 — Langflow
Vulnerability: Inclusion of Functionality from an Untrusted Control Sphere
CVE-2026-0770 is a remote code execution vulnerability affecting Langflow, an open-source platform used to build and manage artificial intelligence workflows and applications.
The vulnerability concerns the handling of the exec_globals parameter within a Langflow validation function. An attacker can supply untrusted functionality that is processed by the application, creating a path to arbitrary code execution on the underlying server.
Authentication is not required for successful exploitation of affected installations. This significantly increases the risk for Langflow services exposed directly to the internet or deployed with insufficient access controls.
Successful exploitation could allow attackers to execute commands, deploy malware, access application data, steal API keys, obtain cloud credentials, extract model information, alter artificial intelligence workflows, or move into connected development and production environments.
Langflow systems can hold connections to databases, cloud platforms, model providers, internal APIs, container environments, and automation services. Compromise of the application can therefore expose credentials and infrastructure extending beyond the affected server.
Organizations should verify the versions deployed throughout their environments, apply current vendor-supported remediation, remove unnecessary public exposure, and isolate any system for which a secure update or mitigation cannot be confirmed.
CVE-2026-63030 — WordPress Core
Vulnerability: Interpretation Conflict
CVE-2026-63030 is an interpretation-conflict vulnerability affecting the WordPress REST API batch endpoint.
The vulnerability causes WordPress components to interpret a request differently during processing, allowing an attacker to bypass intended restrictions and reach functionality that should not be available without authorization.
When chained with CVE-2026-60137, the flaw can allow an unauthenticated attacker to perform SQL injection and progress toward remote code execution on an affected WordPress installation.
Affected versions include WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1. Fixes are available in WordPress 6.9.5 and WordPress 7.0.2.
The WordPress security team enabled forced updates through the automatic-update system because of the severity of the vulnerabilities. Administrators should still verify that every website successfully received the appropriate security release.
Successful exploitation could allow attackers to create unauthorized administrative accounts, alter website content, access protected information, upload malicious files, install backdoors, deploy web shells, redirect visitors, or use compromised websites to distribute malware.
CVE-2026-60137 — WordPress Core
Vulnerability: SQL Injection
CVE-2026-60137 is a SQL injection vulnerability affecting the author__not_in parameter used by WordPress Core’s WP_Query functionality.
The vulnerability results from improper sanitization of data passed to the affected parameter. A vulnerable plugin, theme, or core interaction can allow attacker-controlled input to modify database queries.
SQL injection can provide unauthorized access to database contents, account information, password hashes, configuration records, application data, and other information stored within the WordPress database.
When CVE-2026-60137 is chained with CVE-2026-63030 on WordPress 6.9 and later affected versions, an unauthenticated attacker can bypass access restrictions and use the combined vulnerabilities to achieve remote code execution.
CVE-2026-60137 affects WordPress 6.8.0 through 6.8.5, WordPress 6.9.0 through 6.9.4, and WordPress 7.0.0 through 7.0.1. Fixes are available in WordPress 6.8.6, WordPress 6.9.5, and WordPress 7.0.2.
WordPress versions before 6.8 are not affected by CVE-2026-60137. WordPress 6.8 is affected by the SQL injection vulnerability but not the REST API batch-route vulnerability tracked as CVE-2026-63030.
The combination of these WordPress vulnerabilities creates a serious threat because exploitation can occur against WordPress Core without depending on a vulnerable third-party plugin. Organizations should not assume that maintaining updated plugins and themes protects a site running an affected WordPress version.
Operational Impact
Organizations operating affected systems could face:
- Remote code execution
- Router compromise
- Unauthorized network configuration changes
- Website takeover
- Database theft
- Administrative account creation
- Credential and password-hash exposure
- API key and cloud-secret theft
- Malicious modification of artificial intelligence workflows
- Deployment of web shells and backdoors
- Botnet enrollment
- Distributed denial-of-service activity
- Traffic interception or redirection
- Lateral movement across enterprise networks
- Long-term attacker persistence
- Malware or ransomware deployment
- Website defacement
- Data theft
- Business disruption
The affected products occupy three different areas of enterprise infrastructure. DD-WRT devices can provide access at the network edge, Langflow systems can connect attackers to artificial intelligence and cloud environments, and WordPress installations can expose websites, databases, administrative accounts, and public-facing infrastructure.
Compromise of any one of these technologies can create opportunities for attackers to reach additional systems, steal credentials, alter trusted services, or establish persistence beyond the initially affected product.
Federal Response
CISA added the four vulnerabilities to the Known Exploited Vulnerabilities Catalog under Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk.
The directive establishes mandatory vulnerability-management requirements for Federal Civilian Executive Branch agencies and prioritizes actively exploited vulnerabilities affecting publicly exposed systems capable of granting attackers total control following exploitation.
When required under BOD 26-04, agencies must determine whether affected systems were compromised before security updates or mitigations were applied. Installing a patch does not remove malware, unauthorized accounts, web shells, altered configurations, stolen credentials, or persistence mechanisms established before remediation.
Federal agencies operating affected DD-WRT, Langflow, or WordPress systems must identify vulnerable assets, apply required updates or mitigations, and complete appropriate compromise assessments within the remediation periods established by CISA.
Although BOD 26-04 applies specifically to federal civilian agencies, CISA encourages private-sector organizations, critical infrastructure operators, healthcare providers, educational institutions, financial organizations, state governments, local governments, and technology providers to adopt the same risk-based vulnerability-management strategy.
KEV Catalog Continues to Expand
CISA continues expanding the Known Exploited Vulnerabilities Catalog as additional evidence of active exploitation becomes available.
Security researchers, software vendors, government agencies, and cybersecurity professionals who identify actively exploited vulnerabilities may submit them for consideration through CISA’s KEV nomination process.
To qualify for inclusion, a vulnerability must have an assigned CVE identifier, verified evidence of active exploitation, and clear mitigation guidance.
The KEV Catalog allows organizations to prioritize vulnerabilities based on confirmed attacker activity instead of relying entirely on severity scores. A vulnerability with a lower numerical rating can present an immediate operational threat when attackers are successfully exploiting it against exposed systems.
Defensive Guidance
Organizations operating affected systems should:
- Apply available security updates immediately.
- Update DD-WRT devices to build 45724 or later.
- Disable UPnP when it is not operationally required.
- Restrict router administration and UPnP services to trusted internal networks.
- Identify every DD-WRT device operating throughout the organization.
- Update WordPress 6.8 installations to version 6.8.6.
- Update WordPress 6.9 installations to version 6.9.5.
- Update WordPress 7.0 installations to version 7.0.2.
- Verify that automatic WordPress security updates completed successfully.
- Apply vendor-recommended mitigations for CVE-2026-0770, or discontinue use if effective mitigations are unavailable.
- Remove Langflow systems from public exposure when external access is unnecessary.
- Restrict Langflow access through trusted networks, virtual private networks, firewalls, or identity-aware access controls.
- Review affected systems for indicators of compromise before and after remediation.
- Inspect WordPress installations for unauthorized administrator accounts.
- Search WordPress directories for unfamiliar PHP files, web shells, modified core files, and malicious scheduled tasks.
- Review database activity for suspicious queries, unexpected account changes, and unauthorized data access.
- Examine Langflow logs for suspicious requests involving validation functions or the exec_globals parameter.
- Audit connected cloud credentials, API keys, database passwords, model-provider tokens, and Kubernetes secrets.
- Rotate credentials exposed to affected systems if compromise is suspected.
- Inspect DD-WRT devices for unauthorized configuration changes, altered DNS settings, unfamiliar administrative accounts, and unexpected outbound connections.
- Replace unsupported routers and other end-of-life network equipment.
- Conduct enterprise-wide scans to locate forgotten or unmanaged WordPress, Langflow, and DD-WRT assets.
- Maintain continuous monitoring after remediation to identify delayed or persistent attacker activity.
Forecast — 30 Days
- Continued internet-wide scanning for vulnerable WordPress, Langflow, and DD-WRT installations.
- Accelerated exploitation of internet-facing WordPress websites that have not received the latest security releases.
- Expanded attempts to chain CVE-2026-63030 and CVE-2026-60137 for unauthorized administrative access and remote code execution.
- Continued targeting of exposed Langflow services for code execution, credential theft, and access to connected artificial intelligence infrastructure.
- Additional attempts to compromise DD-WRT routers for botnet enrollment, scanning, traffic manipulation, and distributed denial-of-service operations.
- Increased publication and modification of automated exploitation tools.
- Elevated incident-response activity involving compromised WordPress websites and artificial intelligence development platforms.
- Accelerated remediation across federal agencies, critical infrastructure organizations, hosting providers, and managed service environments.
- Continued additions to CISA’s KEV Catalog as new evidence of active exploitation is confirmed.
TRJ Verdict
The addition of four vulnerabilities affecting DD-WRT, Langflow, and WordPress Core demonstrates that threat actors continue targeting foundational technologies positioned at the network edge, inside artificial intelligence development environments, and across public-facing web infrastructure.
The WordPress vulnerabilities present a particularly urgent threat because they can be chained to transform a database injection weakness into unauthenticated remote code execution against affected core installations. The Langflow vulnerability exposes artificial intelligence infrastructure and the credentials connected to those environments, while the DD-WRT vulnerability demonstrates that older flaws remain operationally valuable when vulnerable network devices remain active.
Organizations should treat this KEV update as an immediate security event. Applying updates is only the first step. Administrators must identify exposed assets, review systems for evidence of prior exploitation, rotate potentially compromised credentials, remove unauthorized persistence, and continue monitoring after remediation. Confirmed active exploitation means the risk is already present, and delayed action gives attackers additional time to compromise systems that remain vulnerable.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



