CISA cybersecurity vulnerability alerts (multiple CVEs)

Six critical and high-severity vulnerabilities disclosed: DD-WRT stack buffer overflow (CVE-2021-27137), Langflow code execution flaws (CVE-2026-0770, CVE-2026-55255), WordPress Core interpretation conflict (CVE-2026-63030), Microsoft AD FS access control gap (CVE-2026-56155), and Oracle E-Business Suite privilege escalation (CVE-2026-46817). All pose remote compromise risks.

12 reports · 11 independentother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

(CISA TS-SOC) CVE-2021-27137 – DD-WRT Stack-Based Buffer Overflow Vulnerability Severity: HIGH Impact Summary: Allows unauthenticated attackers to execute arbitrary code on the device via a stack-base

mastodon:infosec-exchangeother67d ago kagi ↗

(CISA TS-SOC) CVE-2021-27137 – DD-WRT Stack-Based Buffer Overflow Vulnerability Severity: HIGH Impact Summary: Allows unauthenticated attackers to execute arbitrary code on the device via a stack-based buffer overflow in the UPnP component.... https:// thecybermind.co/2026/07/24/cis a-ts-soc-cve-2021-27137-dd-wrt-stack-based-buffer-overflow-vulnerability/

(CISA TS-SOC) CVE-2026-0770 – Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected

mastodon:infosec-exchangeother67d ago kagi ↗

(CISA TS-SOC) CVE-2026-0770 – Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected installations. Timestamp: 2026-07-24T01:31:37.336Z ATT&CK Mapping…... https:// thecybermind.co/2026/07/24/cis a-ts-soc-cve-2026-0770-langflow-inclusion-of-functionality-from-untrusted-control-sphere-v

(CISA TS-SOC) CVE-2026-63030 – WordPress Core Interpretation Conflict Vulnerability Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform S

mastodon:infosec-exchangeother67d ago kagi ↗

(CISA TS-SOC) CVE-2026-63030 – WordPress Core Interpretation Conflict Vulnerability Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform SQL Injection, which may be chained to achieve Remote Code Execution.... https:// thecybermind.co/2026/07/24/cis a-ts-soc-cve-2026-63030-wordpress-core-interpretation-conflict-vulnerability/

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026

mastodon:infosec-exchangeother67d ago kagi ↗

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations.... https:// thecybermind.co/2026/07/24/cis a-ts-soc-cve-2026-60137-wordpress-core-sql-injection-vulnerability/

(CISA TS-SOC) CVE-2026-16232 – Check Point SmartConsole Improper Authentication Vulnerability Severity: CRITICAL Impact Summary: An unauthenticated remote attacker can obtain an application login toke

mastodon:infosec-exchangeother67d ago kagi ↗

(CISA TS-SOC) CVE-2026-16232 – Check Point SmartConsole Improper Authentication Vulnerability Severity: CRITICAL Impact Summary: An unauthenticated remote attacker can obtain an application login token and use it to authenticate with full administrative privileges.... https:// thecybermind.co/2026/07/24/cis a-ts-soc-cve-2026-16232-check-point-smartconsole-improper-authentication-vulnerability/

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via dese

mastodon:infosec-exchangeother67d ago wire ×2 kagi ↗

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data.... https:// thecybermind.co/2026/07/24/cis a-ts-soc-cve-2026-50522-microsoft-sharepoint-deserialization-of-untrusted-data-vulnerability/

(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on

mastodon:infosec-exchangeother66d ago kagi ↗

(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on the affected system via crafted HTTP requests.... https:// thecybermind.co/2026/07/25/cis a-ts-soc-cve-2026-39808-fortinet-fortisandbox-os-command-injection-vulnerability/

(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating syste

mastodon:infosec-exchangeother66d ago kagi ↗

(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating system commands on affected FortiSandbox products via HTTP.... https:// thecybermind.co/2026/07/25/cis a-ts-soc-cve-2026-25089-fortinet-fortisandbox-os-command-injection-vulnerability/

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability Severity: HIGH Impact Summary: Allows an authorized attacker to l

mastodon:infosec-exchangeother66d ago kagi ↗

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control.... https:// thecybermind.co/2026/07/25/cis a-ts-man-cve-2026-56155-microsoft-active-directory-federation-services-insuffici

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to anothe

mastodon:infosec-exchangeother66d ago kagi ↗

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls.... https:// thecybermind.co/2026/07/25/cis a-ts-man-cve-2026-55255-langflow-authorization-bypass-through-use

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, pot

mastodon:infosec-exchangeother66d ago kagi ↗

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover.... https:// thecybermind.co/2026/07/25/cis a-ts-man-cve-2026-46817-oracle-e-business-suite-improper-privilege-management-vulnerability/