Exposure Signal Digest

What moved
this week

Week of July 28, 2026

By Jonathan Risto

Your CVE score is data. The change is the signal.

Get the digest in your inbox.

The week's movers, every Tuesday. No noise, just what changed.


Why this digest exists

Most CVEs never move.
We watch the ones that do.

Exploitation probability spikes overnight. Public exploits land. CVEs cross into confirmed in-the-wild use. That movement, the change, is what ESIP scores and surfaces.

Silence is not clearance: a CVE that didn't move isn't a safe one, just one nothing has happened to this week. When something does move, that change is the exposure signal.

4
Escalating this week
8
New KEV additions
1
Newly weaponized

What moved this week

The movers.

Mover #1 · KEV-confirmed exploitation
WordPress core (SQL injection)
CriticalConfirmedVerified
Weakness: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
What changed this week
A public PoC landed on ExploitDB (wp2shell), days after CISA confirmed exploitation.
Why it matters

A SQL injection in WordPress core, government-confirmed as exploited and now with a public PoC. High velocity, evidence accumulating fast — treat as immediate.

Mover #2 · Confirmed · likelihood rising
DD-WRT router firmware
CriticalConfirmedVerified
Weakness: CWE-121 Stack-based Buffer Overflow
What changed this week
EPSS exploitation probability climbed sharply (0.11 → 0.16) on a KEV-confirmed flaw.
Why it matters

A confirmed-exploited stack overflow in DD-WRT’s UPnP stack, with exploitation probability rising fast. Escalating at critical severity — treat as immediate.

Mover #3 · Confirmed, now weaponized
Langflow (exec_globals RCE)
CriticalConfirmedVerified
Weakness: CWE-829 Inclusion of Functionality from Untrusted Control Sphere
What changed this week
A weaponized exploit landed on ExploitDB (entry 52597).
Why it matters

Government-confirmed exploitation, corroborated by ENISA EUVD, now with a public weaponized exploit. Act now — don’t wait for more evidence.

Mover #4 · Newly weaponized
Gogs self-hosted Git
HighActiveHigh
Weakness: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
What changed this week
A public PoC landed on ExploitDB, followed by a Metasploit module.
Why it matters

Command injection in a self-hosted Git service, weaponized just three days ago. The threat picture is changing fast — review against your inventory.


New confirmed exploitation

Newly confirmed exploited this week.

VMware VeloCloud Orchestrator (on-prem)
Jul 27
Sensitive information exposure
Jul 27
Check Point management (authentication bypass)
Jul 22
Microsoft Office SharePoint (deserialization)
Jul 22
WordPress core (SQL injection)
Jul 21
DD-WRT router firmware (UPnP)
Jul 21
Langflow (exec_globals RCE)
Jul 21
WordPress core
Jul 21

Newly weaponized

New public exploits this week.

Gogs self-hosted Git (Metasploit)
Jul 25

The week in numbers

Stop patching by static score.

1,660
Active Critical signals
49
Active High signals
4
Escalating this week
8
New KEV additions
1
New weaponized exploit

Updated every Tuesday. Subscribe to get it by email.

Look up any CVE Get a free API key →