WordPress Core wp2shell flaws land on CISA KEV
The headline for the last two days is WordPress. On July 21 CISA added two WordPress Core vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-63030, an interpretation conflict flaw carrying a CVSS score of 9.8, and CVE-2026-60137, a SQL injection issue at 5.9. Chained together they form what researchers are calling wp2shell, a remote code execution path in WordPress Core itself rather than a plugin.
BleepingComputer reports the wp2shell chain is already being used to install webshells, and SANS ISC observed exploitation underway for CVE-2026-63030 on July 20. Dark Reading frames the exposure as millions of sites open to remote takeover. Tenable has published a frequently asked questions writeup on the chain. A KEV listing plus confirmed webshell deployment moves this from patch eventually to patch now. Update WordPress Core to a fixed release and hunt for unexpected PHP files in your web roots.
Langflow and older KEV additions
CISA also added CVE-2026-0770 in Langflow on July 21, a functionality-inclusion flaw scored 9.8. BleepingComputer notes CISA ordered federal agencies to take urgent action on an actively exploited Langflow RCE, and a second Langflow authorization bypass, CVE-2026-55255 at CVSS 9.9, is among the hottest movers. If you run Langflow anywhere near production data, treat both as immediate.
Rounding out the July 21 KEV adds is CVE-2021-27137, a stack-based buffer overflow in DD-WRT scored 8.1. That one matters mostly for anyone running DD-WRT firmware on network gear.
SharePoint attacks continue and Exchange update carries KEV
The SharePoint wave has not slowed. SecurityWeek describes a fourth SharePoint vulnerability exploited in the past month's attacks, and Help Net Security along with BleepingComputer both stress the same follow-up for CVE-2026-50522: patch, then rotate your machine keys, because attackers are stealing them. CERT-EU issued advisory 2026-009 on the critical SharePoint flaw. If you patched but did not rotate keys, you are not done.
On the Microsoft side, KB5094144 for Exchange Server 2019 Cumulative Update 14 covers 8 CVEs and is flagged as KEV-linked, so Exchange administrators should prioritize it. CVE-2026-42897, an Exchange spoofing flaw at CVSS 8.8, and the SharePoint security feature bypass CVE-2026-55040 at 9.1 are also on the hot list.
Do this first
Work the confirmed-exploited items in order of what you actually run:
- Update WordPress Core to close CVE-2026-63030 and CVE-2026-60137, then scan for webshells dropped by the wp2shell chain.
- Patch Langflow for CVE-2026-0770 and CVE-2026-55255; both are actively exploited and CISA has ordered urgent action.
- For SharePoint CVE-2026-50522, confirm the patch is applied and rotate machine keys, per the guidance from Help Net Security and CERT-EU.
- Apply KB5094144 to Exchange Server 2019 CU14; it addresses KEV-listed issues.
- Check your own patch state with Siemserva by Senserva. Its free Microsoft Patch Tracker ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions like the WordPress and Langflow entries daily.
Sources
- BleepingComputer: Critical wp2shell WordPress flaws exploited to install webshells (2026-07-21)
- SANS ISC: WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) (2026-07-20)
- Dark Reading: 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover (2026-07-20)
- Tenable: wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core (2026-07-20)
- BleepingComputer: CISA orders urgent action on actively exploited Langflow RCE flaw (2026-07-22)
- SecurityWeek: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks (2026-07-22)
- Help Net Security: Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) (2026-07-22)
- BleepingComputer: Critical SharePoint RCE flaw exploited to steal machine keys (2026-07-21)
- CERT-EU: 2026-009: Critical Vulnerability in Microsoft SharePoint (2026-07-22)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-23.