Act
active
WordPress CVE-2026-87902 actively exploited for webshell deployment
- Engineer — Act: Active exploitation confirmed — attackers are writing PHP webshells to disk via CVE-2026-87902; patch WordPress immediately and audit wp-content directories and recently modified PHP files for unauthorized shells.
- SOC/IR — Act: Assume-breach posture for any WordPress hosts; hunt for newly created or modified PHP files in web roots, anomalous HTTP requests reaching previously non-existent paths, and OS command execution spawning from web server processes.
- Leader — Plan: Confirm whether the organization runs WordPress and direct engineering to prioritize patching this quarter; active exploitation is under way but this has not yet reached Log4Shell-scale board visibility.
- Signals: CVE-2026-87902 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.