cisaregulatorNewsThe Broadside2 min read

CISA adds four KEV flaws under BOD 26-04

The directive turns KEV triage into an agency obligation, which contractors can no longer treat as advisory hygiene.


TL;DR

CISA added CVE-2021-27137 in DD-WRT, CVE-2026-0770 in Langflow, and two WordPress Core flaws, CVE-2026-63030 and CVE-2026-60137, to the Known Exploited Vulnerabilities Catalog based on active exploitation. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets that grant total post-exploitation control. Government contractors, primes, subcontractors and C3PAOs now have a cleaner compliance baseline, even though CISA’s alert does not spell out the patch timeline or verification mechanics for these four entries.

CISA’s July 21 KEV update is small on volume and large on posture. The agency added four actively exploited vulnerabilities to the Known Exploited Vulnerabilities Catalog: CVE-2021-27137 in DD-WRT, CVE-2026-0770 in Langflow, CVE-2026-63030 in WordPress Core and CVE-2026-60137 in WordPress Core. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation when a KEV-listed Common Vulnerabilities and Exposures entry sits on a publicly exposed asset that would give an attacker total control after exploitation.

That matters because CISA is no longer merely telling agencies to use KEV as a smart input to vulnerability management. The alert ties KEV directly to risk-based patch priority under BOD 26-04, while allowing lower-risk vulnerabilities to wait. That is a practical distinction for agency security teams and for the contractors who operate, assess or support FCEB environments. If the vulnerable service is internet-facing and compromise means full asset control, the work queue is not waiting for a quarterly governance meeting.

The contractor consequence is blunt. Primes, subcontractors and C3PAOs supporting federal civilian systems should treat KEV exposure on public-facing systems as a compliance failure waiting to be found, not as a best-practice gap to be narrated later. CISA also says BOD 26-04 sets basic expectations for checking whether threat actors compromised the system before the patch was applied, so remediation is not just “install update, close ticket.” Someone has to answer the unpleasant question of whether the attacker got there first.

The missing operational detail is still the one practitioners need most: the alert does not state the deadline for these four vulnerabilities or explain how CISA will audit or report agency compliance for this update. That does not make the duty ambiguous. It just means the Monday work is asset exposure, KEV matching, patch or mitigation, and compromise review, in that order.


Published ·Deep Fathom