CISA Adds WordPress Core RFI Vulnerability to KEV Catalog
CISA has added CVE-2026-87902, a WordPress Core Remote File Inclusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-87902 to its catalog of Known Exploited Vulnerabilities (KEV). This designation signifies that malicious cyber actors are actively exploiting this vulnerability in the wild, posing a significant threat to organizations worldwide.
The vulnerability, identified as a Remote File Inclusion (RFI) flaw within the core WordPress software, allows attackers to potentially inject and execute arbitrary files on a vulnerable server. This type of vulnerability is a well-known and frequent attack vector, capable of leading to a complete compromise of the affected system.
CISA's decision to add CVE-2026-87902 to the KEV Catalog is based on concrete evidence of its exploitation. This inclusion triggers specific actions for federal agencies under Binding Operational Directive (BOD) 26-04. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies must prioritize the remediation of vulnerabilities listed in the KEV Catalog, particularly those that grant total control of an asset post-exploitation and are publicly exposed.
BOD 26-04 emphasizes a risk-based approach to vulnerability management, requiring agencies to focus their patching efforts on the most critical threats. The directive also outlines expectations for agencies to investigate potential compromises on systems that were vulnerable before a patch was applied. While BOD 26-04 specifically targets FCEB agencies, CISA strongly encourages all organizations, including private sector entities, to adopt similar risk-based vulnerability management practices.
Remote File Inclusion vulnerabilities in popular content management systems like WordPress are particularly concerning due to the vast number of installations globally. A successful exploitation could allow attackers to deface websites, steal sensitive data, or use the compromised server to launch further attacks.
Organizations are urged to review their WordPress installations and apply any available security updates immediately. While CISA provides the KEV Catalog as a guide, proactive security hygiene, including regular patching and robust network monitoring, remains crucial for defending against evolving cyber threats.
CISA continues to monitor the threat landscape and will add other vulnerabilities to the KEV Catalog as they meet the established criteria, which include having a CVE ID, documented evidence of exploitation, and clear mitigation guidance. Organizations can submit potential KEV additions through CISA's dedicated nomination form.