RDS GoSOC AI — Field Notes AI-powered SOC + 16-framework compliance · 14-day free trial

CISA KEV Alert: WordPress Core Remote File Inclusion Vulnerability Now Actively Exploited

What CVE-2026-87902 Means for Your Patch Timelines, BOD 26-04 Obligations, and Compliance Posture

Published 2026-09-25

# CISA KEV Alert: WordPress Core Remote File Inclusion Vulnerability Now Actively Exploited

CISA has added CVE-2026-87902, a WordPress Core Remote File Inclusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild — making immediate remediation action a regulatory and operational necessity for any organisation running WordPress at scale.

What Happened and What the Rules Require

Remote File Inclusion (RFI) vulnerabilities allow an attacker to force a web application to load and execute a malicious file hosted on a remote server. In the context of WordPress Core, exploitation of this class of vulnerability can grant an attacker full control of the affected asset — including the ability to deploy webshells, exfiltrate data, pivot laterally, and establish persistent access.

CISA's addition to the KEV Catalog is not advisory in nature for federal agencies — it is legally binding. Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch (FCEB) agencies to prioritise rapid remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those where post-exploitation yields total asset control. CVE-2026-87902 squarely meets that threshold.

Beyond federal mandates, the active exploitation status of this vulnerability triggers obligations across the compliance frameworks most organisations already operate under:

Why This Matters Right Now

WordPress powers an estimated 40%+ of the public web, meaning the attack surface is enormous and threat actors know exactly how to weaponise Core-level RFI flaws at scale. Active exploitation confirmed by CISA means automated scanning and exploitation tooling is already in circulation. Unpatched instances are not theoretical targets — they are current ones.

For compliance and security teams, the compounding risk is the cross-framework exposure: a single unpatched WordPress instance could simultaneously create a NIS2 incident report obligation, a SOC 2 finding, a PCI DSS non-conformity, and a HIPAA breach notification trigger — all from one exploited host.

What Your Team Should Do in the Next 7-30 Days

Within 7 days:

Within 30 days:

Start a Free Trial with Every Feature Unlocked

RDS GoSOC AI continuously maps your asset vulnerabilities — including KEV Catalog additions — against all 16 supported compliance frameworks, including NIS2, SOC 2, ISO 27001, HIPAA, and PCI DSS, so your security and compliance posture stays synchronised without manual cross-referencing. Start your 14-day free trial at the RDS GoSOC AI platform — no credit card required, and every paid feature is fully unlocked from day one. Once inside, open the User Guide tab to get oriented quickly, and reach out to Sage, the in-app AI assistant, with any setup or framework-mapping questions.

---

#MSP #ManagedServices #CMMC #FedRamp #CyberSecurity #SOC #SecurityOperations #MSSP #ThreatDetection #Compliance #CloudSecurity #IdentitySecurity #SecurityMonitoring #ITServices #CyberResilience #ManagedSecurity #BusinessGrowth

Start the 14-day free trial →