Security & FraudNews date: Published by Svertok:

CISA flags an actively exploited WordPress Core flaw

CVE-2026-87902 is now in the federal Known Exploited Vulnerabilities Catalog, raising its remediation priority for exposed systems.

A paper trail emerges through a breached digital wall beside a fitted gold repair panel.

WordPress Core vulnerability CVE-2026-87902 is now in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalog. CISA says it added the remote file inclusion flaw after finding evidence of active exploitation, making the entry a prioritization signal rather than proof that any specific site was breached.

CISA describes this type of flaw as a frequent attack route for malicious actors and a significant risk to the federal enterprise. Its notice identifies the affected product and vulnerability category, but does not quantify the number of attacks or name compromised organizations.

What the catalog entry changes

Binding Operational Directive 26-04 applies to Federal Civilian Executive Branch agencies. Under that framework, agencies must rapidly remediate high-risk catalog vulnerabilities on publicly exposed assets when exploitation would grant total control, while lower-risk vulnerabilities can be deferred. The directive also sets basic expectations for checking whether attackers compromised a system before a patch was applied.

That directive does not bind every organization. CISA nevertheless encourages all organizations to use risk-based vulnerability management and prioritize remediation of flaws in the catalog.

Next