CISA Adds Six Exploited Vulnerabilities to KEV from AI Platforms, WordPress, SharePoint, and Network Equipment
CISA has updated its Known Exploited Vulnerabilities catalog with six new entries spanning AI frameworks, WordPress, router firmware, SharePoint, and Check Point SmartConsole, forcing federal agencies to patch critical flaws by mid-July after WatchTowr documented active exploitation of a SharePoint zero-day within hours of public disclosure.
Federal agencies across the U.S. are facing compressed remediation timelines after the Cybersecurity and Infrastructure Security Agency updated its Known Exploited Vulnerabilities catalog with six new entries spanning AI frameworks, content management systems, router firmware, and enterprise network equipment over July 21 and 22, 2026. The rapid addition of these flaws indicates that intelligence corroborating active abuse was confirmed quickly across distinct technology stacks, triggering mandatory patch windows that leave agencies with narrow deadlines to assess impact before exploitation risks escalate further.
On July 21 and 22, the agency added entries covering [DD-WRT buffer overflow (CVE-2021-27137), Langflow remote code execution allowing unauthenticated root access (CVE-2026-0770), WordPress Core interpretation conflict enabling pre-authenticated remote code execution (CVE-2026-63030), and a WordPress SQL injection vulnerability (CVE-2026-60137)], requiring federal agencies to remediate these issues by July 24. The DD-WRT entry targets a buffer overflow in the network routing firmware that continues to affect deployed devices long after its discovery, while the Langflow flaw highlights risks in AI platform infrastructure where an attacker can gain complete control without authentication. The WordPress Core defects address vulnerabilities compromising core integrity, with the interpretation conflict allowing code execution before any user authentication and the SQL injection threatening data storage directly.
Two additional entries added on July 22 focus on high-severity flaws in Microsoft SharePoint and Check Point SmartConsole, specifically CVE-2026-50522 involving SharePoint deserialization of untrusted data with a CVSS score of 9.8 and CVE-2026-16232 representing an authentication bypass in SmartConsole that grants unauthenticated full administrative access with a CVSS rating of 9.3. WatchTowr documented active exploitation of the SharePoint zero-day within hours of a public proof-of-concept being released on July 20, noting that attackers stole SharePoint machine keys to maintain persistence even after the underlying flaw was patched. Federal agencies must fix these flaws by July 25, leaving days to address defects that WatchTowr has already seen weaponized in real-world campaigns.
The inclusion of Langflow and DD-WRT underscores the diverse attack surface facing federal infrastructure, where modern AI development workflows coexist with legacy router firmware that remains exposed years after initial disclosure. Simultaneously, the SharePoint vulnerability forces agencies to consider dwell time implications, given WatchTowr’s reporting that weaponization began almost immediately upon public disclosure. The Check Point authentication bypass is particularly critical for network security management, as unauthenticated administrative access could allow an adversary to reconfigure defenses themselves while they operate within the environment.
CISA’s Known Exploited Vulnerabilities catalog does not merely document risks; it enforces remediation deadlines that prioritize specific active threats over other pending issues. The compressed schedule for these six entries ensures that defects in collaboration tools, router firmware, and AI platforms are treated with urgency proportional to their exploitation status. Agencies must execute fixes across this broad range of systems while anticipating that the SharePoint machine key theft described by WatchTowr represents a retention technique that persists beyond the vulnerability itself, making rapid detection and containment as important as the patching itself.