KEVIntel
Latest — 21 Jul 2026

CVE-2026-0770 Exploited in the Wild: Langflow RCE Added to CISA KEV

KEVIntel first observed remote code execution attempts against Langflow’s code-validation endpoint on 27 June 2026, 24 days before CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog. Between 27 June and 21 July, KEVIntel sensors retained 137 exploitation attempts from 46 unique source IP addresses. The

12 min read

More issues

Critical WordPress wp2shell Vulnerability Allows Unauthenticated Remote Code Execution

Two critical vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve unauthenticated remote code execution. The vulnerability chain, publicly referred to as wp2shell, affects WordPress Core rather than a third-party plugin. An attacker does not require a valid WordPress account,
17 Jul 2026 6 min read

What Is a Known Exploited Vulnerability (KEV)?

At KEVIntel, a known exploited vulnerability, commonly shortened to KEV, is a vulnerability for which there is credible evidence of real-world exploitation attempts. A CVE identifies a publicly documented vulnerability. KEV intelligence shows that attackers are trying to exploit a vulnerability, sometimes before a CVE has been assigned or
08 Jul 2026 8 min read

About

KEVIntel

KEVIntel

Know what attackers are exploiting. See the evidence behind it.

Topics

KEVIntel © 2026
  • Sign up
Powered by Ghost