INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CISA Adds Critical WordPress Flaw to Known Exploited Vulnerabilities Catalog

| 2026-09-24 07:12 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 26, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 with a CVSS score of 9.2, to its Known Exploited Vulnerabilities catalog. The vulnerability allows an unauthenticated attacker to make the get_page_template() function include a readable local PHP file outside the active theme directories, potentially leading to remote code execution under specific server and theme conditions. Attackers are using [IOC HIDDEN • LOGIN REQUIRED] to write malicious PHP files and execute code, with the vulnerability being actively exploited. This flaw affects every version of WordPress back to 4.7.0, which is nearly a decade old, and has been addressed by releasing version 7.1.2.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-87902 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

Pe•••••.php
pe•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-87902CVE-2026-87902
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎September 22
Threat actors exploited a previously disclosed security defect in WordPress version 7.1.2 immediately after its patch was released on September 22.
infrastructure 7.1.2
‎September 23
Threat actors originating from a small cluster of IP addresses conducted reconnaissance before escalating to active compromises on WordPress targets by September 23.
tactic Reconnaissance
organisation IP
‎September 24, 2026
CISA ordered federal agencies to fix the critical WordPress vulnerability by September 24, 2026.
‎2026/09/24
Threat actors used Pearcmd.php to write malicious PHP files and execute code on vulnerable servers with register_argc_argv enabled, exploiting a path traversal flaw in WordPress' page-template resolution.
organisation CVE-2026-87902
organisation PHP
organisation CMS
organisation Pearcmd.php
infrastructure 8.5
organisation cPanel
infrastructure 7.1.2
organisation WordPress
infrastructure 4.7
organisation Patchstack
organisation RCE
organisation CVE
organisation AEM Forms
infrastructure 4.7.0
‎September 26, 2026
Threat actors were not mentioned in the snippet, so I will provide a neutral sentence: The U.S. CISA added WordPress flaw to its Known Exploited Vulnerabilities catalog on September 26, 2026.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution WordPress
Tactical Metrics
Metrics
infrastructure
‎8.5
Software Version
Metrics
infrastructure
‎7.1.2
Software Version
Metrics
infrastructure
‎4.7
Software Version
Metrics
infrastructure
‎4.7.0
Software Version
Intelligence Sources