US CISA adds critical software flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog with several high‑severity software flaws. Added entries include a stack‑based buffer overflow in DD‑WRT (CVE‑2021‑27137, CVSS 8.1), a remote code execution issue in Langflow (CVE‑2026‑0770, CVSS 9.8), and two critical WordPress Core weaknesses – a REST API batch‑route confusion bug (CVE‑2026‑63030) and an SQL injection in the author__not_in parameter (CVE‑2026‑60137), both scored 9.8 and 5.9 respectively. Public proof‑of‑concept exploits are available, prompting CISA to recommend immediate updates for affected WordPress versions.
CISA also issued an urgent warning on a critical authentication vulnerability in Check Point SmartConsole (CVE‑2026‑16232, CVSS 9.3) that allows unauthenticated remote attackers to obtain admin tokens and fully compromise management systems. The agency noted active exploitation in the wild, especially where management interfaces are exposed to the internet. Two additional Check Point flaws – another authentication bypass (CVE‑2026‑62144) and a local privilege escalation in GaiaOS WebUI (CVE‑2026‑62145) – were disclosed, though only the first is currently observed being exploited. Organizations are urged to apply patches and enforce proper access controls.