CVE-2026-87902
- CVSS
- —
- EPSS
- —
- CISA KEV
- Not listed
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage

ServeTheHome / The Next Platform / KitGuru / HotHardware
Hackers Exploit Critical WordPress Flaw Just Hours After Patch Release(opens the publisher's site in a new tab)
If you, your business, or someone you know rely on the use of WordPress in any way, applying patches immediately is essential to prevent possible compromise by a Remote Code Execution (RCE) attack. To be specific, security company Patchstack discovered widespread attacks using the CVE-2026-87902…
SecurityWeek
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.

The Hacker News
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker…
BleepingComputer
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]
Canadian Centre for Cyber Security
WordPress security advisory (AV26-952)
Serial number: AV26-952 Date: September 23, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild. The Cyber Centre encourages users and…
What we observed
No signals recorded