All posts

WordPress wp2shell CVEs added to CISA KEV as attacks spread

The Senserva daily security read, July 23, 2026

WordPress Core wp2shell flaws land on CISA KEV

The headline for the last two days is WordPress. On July 21 CISA added two WordPress Core vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-63030, an interpretation conflict flaw carrying a CVSS score of 9.8, and CVE-2026-60137, a SQL injection issue at 5.9. Chained together they form what researchers are calling wp2shell, a remote code execution path in WordPress Core itself rather than a plugin.

BleepingComputer reports the wp2shell chain is already being used to install webshells, and SANS ISC observed exploitation underway for CVE-2026-63030 on July 20. Dark Reading frames the exposure as millions of sites open to remote takeover. Tenable has published a frequently asked questions writeup on the chain. A KEV listing plus confirmed webshell deployment moves this from patch eventually to patch now. Update WordPress Core to a fixed release and hunt for unexpected PHP files in your web roots.

Langflow and older KEV additions

CISA also added CVE-2026-0770 in Langflow on July 21, a functionality-inclusion flaw scored 9.8. BleepingComputer notes CISA ordered federal agencies to take urgent action on an actively exploited Langflow RCE, and a second Langflow authorization bypass, CVE-2026-55255 at CVSS 9.9, is among the hottest movers. If you run Langflow anywhere near production data, treat both as immediate.

Rounding out the July 21 KEV adds is CVE-2021-27137, a stack-based buffer overflow in DD-WRT scored 8.1. That one matters mostly for anyone running DD-WRT firmware on network gear.

SharePoint attacks continue and Exchange update carries KEV

The SharePoint wave has not slowed. SecurityWeek describes a fourth SharePoint vulnerability exploited in the past month's attacks, and Help Net Security along with BleepingComputer both stress the same follow-up for CVE-2026-50522: patch, then rotate your machine keys, because attackers are stealing them. CERT-EU issued advisory 2026-009 on the critical SharePoint flaw. If you patched but did not rotate keys, you are not done.

On the Microsoft side, KB5094144 for Exchange Server 2019 Cumulative Update 14 covers 8 CVEs and is flagged as KEV-linked, so Exchange administrators should prioritize it. CVE-2026-42897, an Exchange spoofing flaw at CVSS 8.8, and the SharePoint security feature bypass CVE-2026-55040 at 9.1 are also on the hot list.

Do this first

Work the confirmed-exploited items in order of what you actually run:

  • Update WordPress Core to close CVE-2026-63030 and CVE-2026-60137, then scan for webshells dropped by the wp2shell chain.
  • Patch Langflow for CVE-2026-0770 and CVE-2026-55255; both are actively exploited and CISA has ordered urgent action.
  • For SharePoint CVE-2026-50522, confirm the patch is applied and rotate machine keys, per the guidance from Help Net Security and CERT-EU.
  • Apply KB5094144 to Exchange Server 2019 CU14; it addresses KEV-listed issues.
  • Check your own patch state with Siemserva by Senserva. Its free Microsoft Patch Tracker ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions like the WordPress and Langflow entries daily.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-23.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.