CISA Adds Critical WordPress Core Bug to KEV as Exploitation Confirmed

Critique · CISA Advisories ·

WordPress · CISA KEV · Exploité

Vérification: The advisory is future-dated relative to the current date and describes an implausible WordPress Core remote file inclusion, undermining its verifiability.

En bref

  • CVE-2026-87902 affects WordPress Core and permits remote file inclusion.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-25.
  • Evidence points to ongoing exploitation, with asset takeover and federal enterprise exposure.
  • Federal agencies must prioritize remediation; other WordPress users should treat it as urgent.

On 2026-09-25, CISA placed a critical WordPress Core vulnerability, tracked as CVE-2026-87902, into its Known Exploited Vulnerabilities catalog. The listing follows evidence that malicious cyber actors are actively exploiting the flaw. Because the issue allows remote file inclusion, an attacker could inject and execute unauthorized code on vulnerable systems.

The consequences extend beyond a single site. Successful exploitation can lead to asset takeover, meaning attackers may gain control of affected web properties and the data or services they support. For federal agencies, this creates federal enterprise risk, especially where WordPress powers public-facing sites, internal portals, or shared hosting environments.

The scope is one vulnerability, but its reach is broad. Any federal agency running an unpatched WordPress Core installation should assume it is a target. The KEV designation signals that remediation is not optional; it is a time-bound priority. While the initial alert focuses on federal agencies, the same exposure applies to state, local, and education networks that rely on WordPress.

WordPress is widely deployed across K-12 districts and government websites, often with limited dedicated security staff. A remote file inclusion bug in Core can bypass typical content-level protections and provide a foothold for lateral movement or persistent access. The active exploitation evidence raises the urgency because waiting for a scheduled maintenance window may be too late.

What to watch: confirm whether your WordPress Core version is affected, monitor for vendor patches and CISA updates, and review web server logs for unusual file inclusion attempts. If compromise is suspected, isolate the host, preserve logs, and begin incident response. The key takeaway is that this is a critical, exploited vulnerability requiring immediate action.

À faire maintenant

  1. Inventory all WordPress Core installations and confirm versions against the CVE-2026-87902 advisory.
  2. Apply the vendor-supplied patch or upgrade to a fixed WordPress Core release immediately; do not wait for routine maintenance.
  3. If patching is not possible, isolate affected sites behind a WAF, restrict file inclusion paths, and disable unnecessary plugins or themes.
  4. Review web and application logs for signs of remote file inclusion, webshells, or unexpected file changes.
  5. Rotate administrative credentials, API keys, and salts for any site that may have been exposed.
  6. Report confirmed or suspected compromises to CISA and your internal incident response team; follow KEV remediation timelines.
  7. For K-12 and government hosts, prioritize internet-facing WordPress assets and verify backups are clean before restoration.

Références CVE

  • CVE-2026-87902

Source originale

CISA Advisories

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber