The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

CISA's addition of CVE-2026-87902 to its KEV catalog on Sept 25 (due Sept 28) is corroborated by NVD, SecurityWeek, Wordfence, Help Net Security, and other outlets.

Sourcing
1source

via CISA

CISA · track record
2Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/CISA Adds WordPress Core Flaw CVE-2026-87902 to KEV Catalog
VERIFIEDBy Xavier Rivera· ·1.5 min read

CISA Adds WordPress Core Flaw CVE-2026-87902 to KEV Catalog

CISA added CVE-2026-87902, a WordPress Core remote file inclusion flaw, to its KEV catalog with a September 28 federal deadline. WordPress 7.1.2 fixes it, and the fix is backported to every branch back to 4.7.

Source:CISA
Post
CISA Adds WordPress Core Flaw CVE-2026-87902 to KEV Catalog
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

CISA added CVE-2026-87902, a remote file inclusion flaw in WordPress Core, to its Known Exploited Vulnerabilities catalog on September 25 with a September 28 due date for federal agencies. The bug can let an unauthenticated attacker load a local .php file through page-template resolution, leading to code execution when certain theme and server conditions are met. WordPress 7.1.2 fixes it, with backports to branches back to 4.7.

CISA added CVE-2026-87902, a remote file inclusion vulnerability in WordPress Core, to its Known Exploited Vulnerabilities catalog on September 25 and gave federal agencies until September 28 to act on it.

The bug sits in how WordPress resolves page templates. According to the WordPress security advisory, an unauthenticated attacker can get get_page_template() to load a readable local .php file from outside the active theme's folders. When specific server and theme conditions line up, that can end in remote code execution.
POST FROM @CISACyber· official CISA Cyber announcement tweet referencing the exact CVE addition to KEV Catalog
https://x.com/CISACyber/status/2103568824733667774
Exposure depends on the active theme and the server setup. WordPress says the active parent or child theme must have a top-level folder whose name begins with "page-", which covers the older Twenty Twelve and Twenty Fourteen themes plus third-party themes such as Neve, Hestia and Sydney. The attacker also needs a usable .php file on the server; the advisory points to PEAR's pearcmd.php when register_argc_argv is enabled, which applies to the official PHP Docker image and to default cPanel setups on PHP versions older than 8.5.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
WordPress 7.1.2 carries the fix, with backports to 4.7. WordPress also shipped the patch to older branches, including 7.0.6, 6.9.9 and 6.8.10, and to every branch back to 4.7.

NVD and WordPress score the flaw differently. The NVD record, published September 22, lists a CVSS 3.1 score of 8.1 (High) from CISA's ADP team, with high attack complexity and no privileges or user interaction required. The WordPress advisory rates it critical at 9.2 under CVSS 4.0.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
CISA's entry sets a three-day window for federal agencies. Agencies must apply vendor mitigations under BOD 26-04, including its forensic triage requirements, or stop using the product if mitigations are unavailable. CISA lists ransomware use as unknown.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
More fromCISA
  • CISA Adds Google Pixel Modem Flaw CVE-2026-58704 to KEV Catalog

    Tech · 22d
More inTech
  • Critical CVE-2026-16823 hits IBM Security Verify Access

    Tech · 14h
  • Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Tech · 15h
  • Bloomberg: Apple plans first touchscreen MacBook Pros for October 27

    Tech · 15h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    GlobalFoundries signs $2B TSMC deal for US silicon interposers

    GlobalFoundries signed a multi-year US$2 billion agreement with TSMC on October 8, 2026 to manufacture silicon interposers at its Malta, New York fab. The deal creates the first US-based source of silicon interposers for TSMC's CoWoS advanced packaging ecosystem.

  • Tech· 

    SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    SpaceX has agreed to acquire Grain Management's nationwide 800 MHz spectrum portfolio, which it says will pave the way for Starlink Mobile to become a major US mobile carrier. The deal needs FCC approval, and financial terms were not disclosed.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.