CISA Adds One Known Exploited Vulnerability to Catalog
Summary
CISA has added CVE-2026-87902, a WordPress Core Remote File Inclusion Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize patching vulnerabilities listed in the KEV Catalog on publicly exposed assets.
IFF Assessment
The addition of a new exploited vulnerability to CISA's KEV catalog indicates active threats that defenders need to address.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 28, 2026. Known ransomware use: Unknown.
Defender Context
This alert signifies that CVE-2026-87902 is actively being exploited in the wild, posing an immediate risk to organizations using affected WordPress Core versions. Defenders should prioritize patching or implementing mitigations for this vulnerability to prevent potential compromise.