Security & FraudNews date: Published by Svertok:
CISA flags an actively exploited WordPress Core flaw
CVE-2026-87902 is now in the federal Known Exploited Vulnerabilities Catalog, raising its remediation priority for exposed systems.

WordPress Core vulnerability CVE-2026-87902 is now in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalog. CISA says it added the remote file inclusion flaw after finding evidence of active exploitation, making the entry a prioritization signal rather than proof that any specific site was breached.
CISA describes this type of flaw as a frequent attack route for malicious actors and a significant risk to the federal enterprise. Its notice identifies the affected product and vulnerability category, but does not quantify the number of attacks or name compromised organizations.
What the catalog entry changes
Binding Operational Directive 26-04 applies to Federal Civilian Executive Branch agencies. Under that framework, agencies must rapidly remediate high-risk catalog vulnerabilities on publicly exposed assets when exploitation would grant total control, while lower-risk vulnerabilities can be deferred. The directive also sets basic expectations for checking whether attackers compromised a system before a patch was applied.
That directive does not bind every organization. CISA nevertheless encourages all organizations to use risk-based vulnerability management and prioritize remediation of flaws in the catalog.
Next

CISA flags an actively exploited Apple out-of-bounds write flaw
CVE-2026-86950 now appears in CISA’s Known Exploited Vulnerabilities Catalog, although the alert does not identify specific Apple models, victims or attack volume.
Read next
