INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CISA Adds Critical WordPress Flaw to Known Exploited Vulnerabilities Catalog
| 2026-09-24 07:12 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 26, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 with a CVSS score of 9.2, to its Known Exploited Vulnerabilities catalog. The vulnerability allows an unauthenticated attacker to make the get_page_template() function include a readable local PHP file outside the active theme directories, potentially leading to remote code execution under specific server and theme conditions. Attackers are using [IOC HIDDEN • LOGIN REQUIRED] to write malicious PHP files and execute code, with the vulnerability being actively exploited. This flaw affects every version of WordPress back to 4.7.0, which is nearly a decade old, and has been addressed by releasing version 7.1.2.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-87902 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
Pe•••••.php
pe•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-87902CVE-2026-87902
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
September 22
Threat actors exploited a previously disclosed security defect in WordPress version 7.1.2 immediately after its patch was released on September 22.
Click on any entity below to view its context and source!
infrastructure
7.1.2
The security defect was addressed on September 22 in WordPress
version 7.1.2
.
September 23
Threat actors originating from a small cluster of IP addresses conducted reconnaissance before escalating to active compromises on WordPress targets by September 23.
Click on any entity below to view its context and source!
tactic
Reconnaissance
Originating from a small cluster of IP addresses, the initial exploitation activity was designed for reconnaissance, but escalated to active compromises by September 23, Patchstack says.
organisation
IP
Originating from a small cluster of IP addresses, the initial exploitation activity was designed for reconnaissance, but escalated to active compromises by September 23, Patchstack says.
September 24, 2026
CISA ordered federal agencies to fix the critical WordPress vulnerability by September 24, 2026.
2026/09/24
Threat actors used Pearcmd.php to write malicious PHP files and execute code on vulnerable servers with register_argc_argv enabled, exploiting a path traversal flaw in WordPress' page-template resolution.
Click on any entity below to view its context and source!
organisation
CVE-2026-87902
Patchstack suggests that the activity surrounding CVE-2026-87902 is likely to increase, as public scanning tools exist.
CVE-2026-87902
allows an unauthenticated attacker to make the
get_page_template()
function include a readable local PHP file outside the active theme directories.
organisation
PHP
CVE-2026-87902
allows an unauthenticated attacker to make the
get_page_template()
function include a readable local PHP file outside the active theme directories.
The official PHP image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use,” the advisory reads.
organisation
CMS
It stems from how the CMS resolves page templates, with a real path to remote code execution.
organisation
Pearcmd.php
Pearcmd.php provides a command-line tool for the management of PEAR packages in PHP environments and can be abused for RCE on servers with register_argc_argv enabled, especially when combined with a local file inclusion or a path traversal issue.
infrastructure
8.5
The official PHP image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use,” the advisory reads.
organisation
cPanel
The official PHP image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use,” the advisory reads.
infrastructure
7.1.2
This week, WordPress released version 7.1.2 to address this flaw.
organisation
WordPress
This week, WordPress released version 7.1.2 to address this flaw.
The exploitation of a fresh WordPress vulnerability started within hours of public disclosure and has escalated to active compromises, security firm Patchstack warns.
infrastructure
4.7
The fix was also backported to previous WordPress releases, all the way back to 4.7.x.
organisation
Patchstack
The exploitation of a fresh WordPress vulnerability started within hours of public disclosure and has escalated to active compromises, security firm Patchstack warns.
organisation
RCE
If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE,” WordPress’
advisory
reads.
organisation
CVE
“Traffic against this CVE is now running at more than ten times the volume we saw on the first evening; it is reaching a far wider spread of sites, and the requests have moved through three clear stages,” the security firm notes.
organisation
AEM Forms
Adobe Patches Critical Flaws in Connect, AEM Forms
Related:
Chrome 154 Patches 108 Vulnerabilities
Related:
infrastructure
4.7.0
The bug affected every version back to 4.7.0.
September 26, 2026
Threat actors were not mentioned in the snippet, so I will provide a neutral sentence: The U.S. CISA added WordPress flaw to its Known Exploited Vulnerabilities catalog on September 26, 2026.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 26, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 26, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog.
attribution
WordPress
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 26, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog.
Tactical Metrics
Metrics
infrastructure
8.5
Software Version
Click for context!
The official PHP image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use,” the advisory reads.
Metrics
infrastructure
7.1.2
Software Version
The security defect was addressed on September 22 in WordPress
version 7.1.2
.
This week, WordPress released version 7.1.2 to address this flaw.
Metrics
infrastructure
4.7
Software Version
The fix was also backported to previous WordPress releases, all the way back to 4.7.x.
Metrics
infrastructure
4.7.0
Software Version
The bug affected every version back to 4.7.0.
Intelligence Sources
Security Affairs
2026-09-26
SecurityWeek
2026-09-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
IP
entity
8x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
5x
timeline
Temporal Reference
September 23
date
4x
infrastructure
Software Version
8.5
version
2x
tactic
Cyber Operation Type
Reconnaissance
tactic
Contextual Telemetry
Context Block
5 METRICS
vulnerability
Exploited CVE
CVE-2026-87902
cve
vulnerability
CVSS Score
9
score
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Patches
154
patches
general metric
Vulnerabilities
108
vulnerabilities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.