cisaregulatorNewsThe Broadside1 min read

CISA Adds WordPress RFI Bug to KEV Catalog

A remote file inclusion vulnerability in WordPress Core is now a BOD 26-04 priority for every federal agency running a public-facing instance.


TL;DR

CISA added CVE-2026-87902, a WordPress Core Remote File Inclusion vulnerability, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must prioritize remediation on publicly exposed assets under BOD 26-04. The directive also requires agencies to determine whether threat actors compromised systems before the patch was applied. CISA encourages all organizations (not just FCEB) to adopt the KEV catalog as a prioritization input.

WordPress Core joins the KEV catalog this week with a remote file inclusion vulnerability (CVE-2026-87902) that CISA has confirmed is being actively exploited. The addition was published September 25, 2026, the same day as a separate KEV alert covering SharePoint and MikroTik vulnerabilities.

Under BOD 26-04, FCEB agencies must prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets where exploitation grants total control of the asset. The directive also establishes baseline expectations for forensic triage: agencies must check whether threat actors compromised the system before the patch was available. CISA classifies this vulnerability type as "a frequent attack vector for malicious cyber actors" that "poses significant risks to the federal enterprise."

The catalog now runs on a near-weekly cadence of additions through September. Last week brought a Linux kernel CVE; this week brings WordPress, SharePoint, and MikroTik entries across two alerts published within hours of each other. The pattern is steady, not anomalous, KEV additions are a predictable enforcement rhythm tied to BOD 26-04, not a signal of escalation. The operational question for federal security teams is whether their WordPress inventory is complete enough to know which assets the directive covers.


Published ·Deep Fathom