On September 25, 2026, CISA said it had added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw is described as a remote file inclusion vulnerability in the WordPress core, with evidence of active exploitation.
The agency says this type of flaw is a frequent attack vector and can pose significant risk. BOD 26-04 sets requirements for U.S. federal civilian agencies, including prioritizing KEV vulnerabilities on publicly exposed assets where exploitation could grant full control of the asset. The directive also sets expectations for checking for possible compromise before applying a patch.
BOD 26-04 applies only to FCEB agencies. CISA encourages other organizations to use risk-based vulnerability management and prioritize fixes for KEV entries. To apply that guidance, identify potentially affected assets, consult official mitigation instructions, and assess signs of compromise before or during remediation as appropriate.
To verify the notice, consult CISA’s original alert and check the CVE entry in the KEV catalog, comparing the identifier, description, and mitigation guidance. If you use AI to study or adapt the material, do not submit credentials, customer data, or internal system details; use public or anonymized content.