Critical WordPress Core RCE and Three Other Actively Exploited Flaws Hit CISA's KEV Catalog
CISA KEV adds WordPress Core CVE-2026-87902 (RCE), WSO2/Adobe CVE-2026-5430 and Roundcube CVE-2026-48842 — what K-12 and government IT must patch now.
- CISA added CVE-2026-87902, an unauthenticated remote file inclusion flaw in WordPress Core that can lead to remote code execution, to its Known Exploited Vulnerabilities catalog on 25 September 2026.
- CISA also listed CVE-2026-5430 (WSO2 authentication bypass, also linked to Adobe Commerce/Magento and SharePoint), while Canada's Cyber Centre warned that CVE-2026-48842 (Roundcube Webmail pre-auth SQL injection) is being exploited in the wild.
- Any internet-facing WordPress, Roundcube, WSO2 or Adobe Commerce asset in a district or government environment should be treated as at risk until inventoried, patched or isolated.
What to do now
- Inventory every WordPress Core, Roundcube, WSO2 and Adobe Commerce/Magento instance today, note the exact version, and flag which ones are internet-facing; confirm affected and fixed versions against the vendor advisories, since the source summaries do not state a fixed release for CVE-2026-87902.
- Patch first, in this order: WordPress Core (CVE-2026-87902, RCE, confirmed exploitation), Roundcube (CVE-2026-48842 — or disable the virtuser_query plugin if patching is not immediately possible), then WSO2/Adobe Commerce (CVE-2026-5430). Do not wait for the next maintenance window.
- Where patching is blocked, put the site behind a WAF with virtual patching, restrict wp-admin and template-resolution endpoints, disable unused plugins/themes, and isolate the host from sensitive networks.
- Hunt for compromise: review web and application logs for file-inclusion attempts, webshells, unexpected file changes, '../' path traversal patterns, pre-auth requests to virtuser_query, and new or unexpected administrator accounts (relevant to the Elementor CSRF issue).
- Rotate administrative credentials, database and mail passwords, API keys and WordPress salts for any exposed site, invalidate active sessions, verify backups are clean before restoring, and report confirmed or suspected compromises to CISA and your incident response team.
Related items
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
- U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- Elementor WordPress flaw lets attackers create admin accounts
- WordPress Core: WordPress Core Remote File Inclusion Vulnerability
- CISA Adds One Known Exploited Vulnerability to Catalog
- Wordfence Bug Bounty Program Monthly Report – June 2026