# KEVIntel > Research and first-hand telemetry on actively exploited vulnerabilities, attacker activity, CVEs, detection and remediation from KEVIntel. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages _No public content available._ ## Posts - [CVE-2026-0770 Exploited in the Wild: Langflow RCE Added to CISA KEV](https://blog.kevintel.com/cve-2026-0770-exploited-in-the-wild-langflow-rce-added-to-cisa-kev.md) - KEVIntel first observed remote code execution attempts against Langflow’s code-validation endpoint on 27 June 2026, 24 days before CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog. Between 27 June and 21 July, KEVIntel sensors retained 137 exploitation attempts from 46 unique… - [Critical WordPress wp2shell Vulnerability Allows Unauthenticated Remote Code Execution](https://blog.kevintel.com/critical-wordpress-wp2shell-vulnerability-allows-unauthenticated-remote-code-execution.md) - Two critical vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve unauthenticated remote code execution. The vulnerability chain, publicly referred to as wp2shell, affects WordPress Core rather than a third-party plugin. An attacker does not req… - [What Is a Known Exploited Vulnerability (KEV)?](https://blog.kevintel.com/what-is-a-known-exploited-vulnerability-kev.md) - At KEVIntel, a known exploited vulnerability, commonly shortened to KEV, is a vulnerability for which there is credible evidence of real-world exploitation attempts. A CVE identifies a publicly documented vulnerability. KEV intelligence shows that attackers are trying to exploit a vulnerability, so… ## Optional - [RSS Feed](https://blog.kevintel.com/rss/) - [Sitemap](https://blog.kevintel.com/sitemap.xml) - [Full content of pages and posts](https://blog.kevintel.com/llms-full.txt)