Content & Marketing StrategyJul 22, 2026
Patch now: a WordPress core RCE chain and a second Langflow flaw land in CISA's exploited list
On July 21, 2026, CISA added an actively exploited WordPress core chain dubbed wp2shell — a REST API flaw (CVE-2026-63030) plus a SQL injection (CVE-2026-60137) that together give an unauthenticated attacker remote code execution on default installs of WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; fixes shipped in 6.9.5 and 7.0.2. The same update added CVE-2026-0770, a critical (CVSS 9.8) unauthenticated remote-code-execution flaw in the AI agent-building platform Langflow — its second actively exploited flaw in about two weeks, with a federal patch deadline of July 24.
What it means Unpatched WordPress sites are exploitable by anonymous attackers right now, and self-hosted Langflow has hit the exploited list twice in two weeks — treat exposed instances as patch-or-isolate today, not dev tools you can forget.
Where it came from CISA