BVTech News — 10 New KEV Entries Hit WordPress, Langflow, and more — July 22, 2026

By Jordan Polasek · July 22, 2026

CISA just added 10 new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. A KEV listing isn't theoretical — it means attackers are exploiting the flaw right now. Here's each one in plain English, and exactly what a Texas business should do about it.

CVE-2026-60137 — Core

WordPress Core carries a serious flaw (WordPress Core SQL Injection Vulnerability). CISA added it to the KEV catalog on 2026-07-21, with a federal remediation deadline of 2026-08-04 — a 14-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Update the plugin (or core) immediately and delete any plugins you're not actively using — every extra plugin is another door.

CVE-2026-63030 — Core

WordPress Core carries a serious flaw (WordPress Core Interpretation Conflict Vulnerability). CISA added it to the KEV catalog on 2026-07-21, with a federal remediation deadline of 2026-07-24 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Update the plugin (or core) immediately and delete any plugins you're not actively using — every extra plugin is another door.

CVE-2026-0770 — Langflow

Langflow Langflow carries a serious flaw (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability). CISA added it to the KEV catalog on 2026-07-21, with a federal remediation deadline of 2026-07-24 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Apply the vendor's latest security update now, and review logs for signs the flaw was already used before you patched.

CVE-2021-27137 — DD-WRT

DD-WRT DD-WRT carries a serious flaw (DD-WRT Stack-Based Buffer Overflow Vulnerability). CISA added it to the KEV catalog on 2026-07-21, with a federal remediation deadline of 2026-07-24 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Apply the vendor's latest security update now, and review logs for signs the flaw was already used before you patched.

CVE-2026-58644 — SharePoint

Microsoft SharePoint carries a serious flaw (Microsoft SharePoint Deserialization of Untrusted Data Vulnerability). CISA added it to the KEV catalog on 2026-07-16, with a federal remediation deadline of 2026-07-19 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: On-premises servers are the exposure here — patch them today. Microsoft 365/SharePoint Online is patched for you by Microsoft.

CVE-2026-25089 — FortiSandbox

Fortinet FortiSandbox carries a serious flaw (Fortinet FortiSandbox OS Command Injection Vulnerability). CISA added it to the KEV catalog on 2026-07-16, with a federal remediation deadline of 2026-07-19 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: This is an internet-facing edge/security appliance — apply the vendor fix now, and lock its management interface to a private network or VPN so it isn't reachable from the open internet.

CVE-2026-39808 — FortiSandbox

Fortinet FortiSandbox carries a serious flaw (Fortinet FortiSandbox OS Command Injection Vulnerability). CISA added it to the KEV catalog on 2026-07-16, with a federal remediation deadline of 2026-07-19 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: This is an internet-facing edge/security appliance — apply the vendor fix now, and lock its management interface to a private network or VPN so it isn't reachable from the open internet.

CVE-2026-46817 — E-Business Suite

Oracle E-Business Suite carries a serious flaw (Oracle E-Business Suite Improper Privilege Management Vulnerability). CISA added it to the KEV catalog on 2026-07-15, with a federal remediation deadline of 2026-07-18 — a 3-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Patch the affected version now and restrict admin access to a management network; these systems are high-value targets.

CVE-2023-4346 — KNX Protocol Connection Authorization Option 1

KNX Association KNX Protocol Connection Authorization Option 1 carries a serious flaw (KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability). CISA added it to the KEV catalog on 2026-07-15, with a federal remediation deadline of 2026-07-29 — a 14-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Apply the vendor's latest security update now, and review logs for signs the flaw was already used before you patched.

CVE-2026-56155 — Active Directory Federation Services

Microsoft Active Directory Federation Services carries a serious flaw (Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ). CISA added it to the KEV catalog on 2026-07-14, with a federal remediation deadline of 2026-07-28 — a 14-day window, which is CISA telling everyone how fast this needs fixing.

What to do: Apply the vendor's latest security update now, and review logs for signs the flaw was already used before you patched.

The 60-second version

Federal agencies are the only ones legally bound by these deadlines — but the deadline length is CISA telling everyone how fast the house is burning. If you're not sure whether any of this hardware or software is in your environment, that's exactly the question we answer for Texas businesses every day. Ask us.