CuraSec

Act active

WordPress CVE-2026-87902 actively exploited for webshell deployment

2026-09-24 15:49 UTC · BleepingComputer · read the source ↗ #wordpress#rce#active-exploitation
  • Engineer — Act: Active exploitation confirmed — attackers are writing PHP webshells to disk via CVE-2026-87902; patch WordPress immediately and audit wp-content directories and recently modified PHP files for unauthorized shells.
  • SOC/IR — Act: Assume-breach posture for any WordPress hosts; hunt for newly created or modified PHP files in web roots, anomalous HTTP requests reaching previously non-existent paths, and OS command execution spawning from web server processes.
  • Leader — Plan: Confirm whether the organization runs WordPress and direct engineering to prioritize patching this quarter; active exploitation is under way but this has not yet reached Log4Shell-scale board visibility.
  • Signals: CVE-2026-87902 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.