🚨 CRITICAL ALERT: Active Zero-Day Exploits
Multiple CVSS 8.0+ vulnerabilities are currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and should be treated as an immediate incident-response priority. The most urgent risk is CVE-2026-0770, a CVSS 9.8 unauthenticated remote code execution flaw in Langflow that can lead to root-level compromise. CVE-2026-63030 is another CVSS 9.8 issue affecting WordPress 6.9.x/7.0.x, and CVE-2021-27137 remains a high-risk DD-WRT overflow that can be exploited where UPnP is enabled.[1][3][5]
Critical Vulnerabilities (CVSS >= 8.0)
- CVE-2026-0770 (CVSS: 9.8): Langflow remote code execution via unsafe handling of the
exec_globalsparameter at the/validateendpoint. Remote attackers can execute arbitrary code without authentication, and reporting indicates exploitation can yield root-level execution. View NVD | CISA KEV - CVE-2021-27137 (CVSS: 8.1): DD-WRT buffer overflow in
router/upnp/src/ssdp.ccaused by unsafestrcpyin UPnP handling. Exploitation is unauthenticated and remote, but requires UPnP to be enabled; the issue is reachable via anM-SEARCHrequest. View NVD | CISA KEV - CVE-2026-63030 (CVSS: 9.8): WordPress REST API batch endpoint route confusion issue in 6.9.x before 6.9.5 and 7.0.x before 7.0.2. When combined with CVE-2026-60137, it can enable SQL injection and ultimately remote code execution. View NVD | CISA KEV
âš¡ Immediate Actions Required
Patch or isolate affected systems immediately, starting with any internet-exposed Langflow and WordPress instances. For DD-WRT, confirm whether UPnP is enabled; if so, disable it until fixed firmware is deployed. If you cannot patch right away, restrict network access to administrative interfaces, remove public exposure, and monitor for exploit indicators and suspicious child processes, web shells, unexpected outbound connections, or new admin accounts. Treat any exposed Langflow deployment as high probability of compromise until verified clean.

