← Back to Feed

Hackers start exploiting critical WordPress flaw for code execution

CVE-2026-87902

September 23, 2026 · BleepingComputer · Severity: CRITICAL

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.

Key Takeaways

  • Security vulnerabilities (CVE-2026-87902) have been identified, requiring prompt patching and risk assessment to mitigate exploitation risks.
  • According to BleepingComputer, this cybersecurity development warrants attention from security teams monitoring the evolving threat landscape.
  • Given the CRITICAL severity rating, organizations should prioritize this in their vulnerability management workflow.
☕ Buy a Coffee