HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Advisory

CISA Adds Four Actively Exploited CVEs to KEV Catalog, Raising SOC 2 Vulnerability‑Management Stakes

CISA placed four CVEs—including a WordPress core SQL injection and a DD‑WRT buffer overflow—into its Known Exploited Vulnerabilities catalog, signaling active threat activity. Organizations must treat these as high‑priority remediation items to satisfy SOC 2 vulnerability‑management controls.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Known Exploited Vulnerabilities Added to CISA KEV Catalog (CVE‑2021‑27137, CVE‑2026‑0770, CVE‑2026‑63030, CVE‑2026‑60137)

What It Is — The Cybersecurity and Infrastructure Security Agency (CISA) announced that four CVEs have been added to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The flaws span DD‑WRT router firmware (stack‑based buffer overflow), Langflow (untrusted code inclusion), and two separate WordPress core issues (interpretation conflict and a high‑severity SQL injection).

Exploitability — All four have documented exploitation; public exploit code or attacker use has been observed. CVSS scores range from 7.5 to 9.8, indicating high to critical impact.

Affected Products — DD‑WRT firmware (various router models), Langflow AI workflow platform, WordPress core (versions vulnerable to CVE‑2026‑63030 and CVE‑2026‑60137).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 – Vulnerability Management: Demonstrating a risk‑based, documented process for identifying and remediating KEV items satisfies the “timely remediation” requirement.
  • Continuous Evidence: Mapping each CVE to remediation tickets and patch‑deployment logs creates immutable audit evidence for SOC 2 examinations and for any enterprise buyer demanding proof of a robust patch cadence.
  • Risk‑Based Prioritization: CISA’s BOD 26‑04 aligns with the SOC 2 principle of “risk‑based controls,” giving organizations a defensible rationale to prioritize these high‑risk flaws over lower‑severity items.

Recommended Actions

  • Map each CVE to SOC 2 control CC6.1 and record remediation status in your GRC tool.
  • Apply vendor patches or mitigations immediately; if unavailable, implement compensating controls (e.g., network segmentation, WAF rules).
  • Capture patch‑deployment logs, ticket timestamps, and validation scans as continuous compliance evidence.
  • Update your vulnerability‑management policy to reference CISA’s KEV catalog as a high‑priority source.

Source: CISA Advisory – 4 Known Exploited Vulnerabilities Added to KEV Catalog

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →