██████╗██╗   ██╗██████╗ ██████╗     ██████╗██╗  ██╗
 ██╔════╝╚██╗ ██╔╝██╔══██╗██╔══██╗   ██╔════╝╚██╗██╔╝
 ██║      ╚████╔╝ ██████╔╝██████╔╝ ● ██║      ╚███╔╝ 
 ██║       ╚██╔╝  ██╔══██╗██╔══██╗   ██║      ██╔██╗ 
 ╚██████╗   ██║   ██████╔╝██║  ██║   ╚██████╗██╔╝ ██╗
  ╚═════╝   ╚═╝   ╚═════╝ ╚═╝  ╚═╝    ╚═════╝╚═╝  ╚═╝
────────────────────────────────── STAY SHARP ───

WordPress Zero-Days Chained in Wild Attacks, CISA Deadline Looms

Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. July 22, 2026

Share

cybr.cx — Daily Digest · July 22, 2026


Critical Vulnerabilities

⚠️ Actively exploited — CVE-2026-60137 & CVE-2026-63030 | WordPress Core
These two vulnerabilities are being chained in live attacks right now and carry a CISA KEV due date of July 24 for federal agencies. CVE-2026-60137 is a SQL injection flaw triggered when a plugin or theme passes untrusted input to a vulnerable parameter; CVE-2026-63030 is an interpretation conflict that escalates that SQL injection into unauthenticated remote code execution on default WordPress installations. The combination means a completely unpatched, stock WordPress site can be fully compromised with no credentials required. Patch or isolate immediately — this is mass-exploitation territory.

⚠️ Actively exploited — CVE-2026-0770 | Langflow
Langflow, the popular AI workflow orchestration platform, contains a remote code execution vulnerability via inclusion of functionality from an untrusted control sphere. No authentication is required. CISA's due date was July 24, suggesting agencies are already seeing exploitation. If you're running Langflow in any internet-exposed capacity — including internal AI development environments — treat this as a fire drill.

⚠️ Actively exploited — CVE-2021-27137 | DD-WRT
A five-year-old stack-based buffer overflow in DD-WRT's UPnP handler has made it back onto the KEV list, which means someone is actively weaponising it in 2026. An unauthenticated attacker on the network can overflow the internal UPnP buffer to achieve code execution. DD-WRT devices are often forgotten the moment they're installed — audit your edge hardware inventory now.

⚠️ Actively exploited — CVE-2026-58644 | Microsoft SharePoint
A deserialization of untrusted data vulnerability in SharePoint allows unauthenticated network attackers to execute arbitrary code. Deserialization RCE in SharePoint is a well-worn attacker playbook and this one is already in the wild. The patch due date has already passed for federal agencies (July 19); if you haven't applied the fix, you're behind.

⚠️ Actively exploited — CVE-2026-25089 & CVE-2026-39808 | Fortinet FortiSandbox
Both flaws are OS command injection vulnerabilities in FortiSandbox (including Cloud and PaaS variants) exploitable by unauthenticated attackers via crafted HTTP requests. Having your sandboxing infrastructure compromised is a particularly grim outcome — it undermines the detection layer itself. Fortinet customers should verify patch status across all FortiSandbox deployment types.

CVE-2026-64624 | FreeRDP < 3.28.0 | CVSS 7.8
FreeRDP parses lines beginning with / in .rdp files as raw command-line arguments, exposing the full CLI parser to attacker-controlled content. A malicious RDP file can invoke /rdp2tcp for arbitrary command execution, /cert:ignore to silently bypass certificate validation, or /drive to mount local filesystems — all without user interaction beyond opening the file. Update to 3.28.0; be cautious with any externally supplied .rdp files.

CVE-2026-16493 | ansible-core | CVSS 7.8
The _extract_collection_from_git() function builds git clone commands without a -- end-of-options separator, meaning a crafted collection source URI can inject arbitrary git arguments and achieve command execution. This affects anyone installing Ansible collections from git sources — a common pattern in automated pipelines. Validate collection source URIs and update ansible-core as soon as a patched version is available.

CVE-2026-16445 | dracut | CVSS 7.5
A network-adjacent attacker can send crafted DHCP options — malicious root-path, next-server, or bootfile name values — to a system using dracut's NetworkManager-based initrd networking. These options are written unescaped into a temporary shell script during early boot, enabling command injection before the main OS is even running. PXE-boot environments and bare-metal provisioning networks are most exposed.

CVE-2026-16329 / 16331 / 16332 | D-Link DNS-320 1.0.2 | CVSS 7.3
Three separate unrestricted file upload vulnerabilities across different endpoints (uploadify.php, save_ajax.php, multi_uploadify.php) all permit unauthenticated remote file upload on this end-of-life NAS device. Public exploits exist for all three. D-Link DNS-320 reached EOL years ago — if it's still on your network, it should be considered compromised until replaced.


Headline News

Hugging Face Hit by Fully Autonomous AI-Driven Cyberattack

Hugging Face disclosed that its platform came under attack from a fully autonomous AI agent that swarmed its infrastructure, and the response involved an unexpected trade-off: the defensive tooling that proved most effective was a Chinese AI model, after U.S.-based models were hampered by their own safety guardrails during the incident. The attack represents a meaningful shift in threat actor capability — automated agents probing and adapting at machine speed, without a human operator in the loop for each decision. OpenAI has since partnered with Hugging Face on the post-incident response, framing the collaboration around model evaluation security. For defenders, the episode surfaces a practical tension that will only intensify: safety restrictions baked into commercial models may degrade response effectiveness precisely when speed matters most. Security teams evaluating AI-assisted defence tooling should now explicitly test how those tools behave under adversarial conditions, not just normal operating parameters.

Fairlife Production Halted After Cyberattack

Fairlife, the Coca-Cola-owned milk brand, has suspended US production following a cyberattack involving unauthorised access to its systems. The incident is a reminder that operational technology and food production infrastructure remain attractive targets — either for ransomware operators seeking maximum supply-chain leverage or for actors probing critical consumer goods networks. Details on the intrusion vector haven't been confirmed publicly, but production halts of this kind typically follow ransomware deployment or precautionary shutdowns to prevent lateral movement into OT systems. The food and agriculture sector has seen a sustained uptick in targeting over recent years, and incidents with direct physical consequences — halted production lines, disrupted cold chains — continue to prove that cyber events carry real-world operational cost well beyond data theft.

Israeli Spyware Vans Reportedly Operating on US Streets

Reporting has emerged detailing the use of mobile surveillance vans equipped with Israeli-developed technology — linked to vendors including Cognyte and a system called Falconet — operating within the United States and capable of intercepting mobile device data. The vans reportedly function as mobile IMSI catchers or equivalent interception platforms, capable of sweeping phone identifiers and potentially content from passing devices without individual warrants. The story raises acute questions about the legal framework governing domestic use of foreign-sourced interception hardware, particularly given ongoing scrutiny of commercial spyware vendors. For practitioners, the technical implication is practical: signals-level interception at street scale is no longer theoretical, and communications security hygiene — encrypted messaging, avoiding unencrypted voice — matters in physical environments, not just on networks.


Schrödinger's Feed

A joint study from AWS, NVIDIA, Lawrence Berkeley National Laboratory, and NASA has published a quantitative performance model defining when quantum processing units must be physically co-located with classical high-performance computing infrastructure to deliver meaningful advantage. This isn't a headline-grabbing qubit count announcement — it's something more architecturally significant: a framework that tells engineers where quantum hardware actually needs to sit relative to classical compute to avoid latency killing any quantum speedup. For cryptography and security workloads, understanding this integration model matters because the timeline for quantum-capable systems relevant to breaking current encryption depends as much on these engineering constraints as on raw qubit performance. Practitioners working on post-quantum cryptography migration timelines should factor hybrid QPU-HPC architecture maturation into their threat modelling — the bottleneck may be integration, not just qubit count.


/dev/random

Hugging Face revealed that during its autonomous AI cyberattack response, it turned to a Chinese AI model to handle defensive tasks after discovering that American commercial models kept refusing to cooperate — apparently their safety guardrails interpreted the attack-related queries as policy violations. So the security incident spawned a second, subtler incident: a content moderation system declining to help stop a cyberattack because "discussing exploits" triggered the wrong classifier. It's the digital equivalent of your fire extinguisher asking you to confirm you've read the safety manual before releasing foam. Somewhere, a red team is already writing this into their next tabletop scenario.