[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGMgAlupkDbscuF-Wtde_3HT_Pp2OOO3pk-avnrfSga4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"c3851e54-e292-4e77-903b-35116ae3e925","actively-exploited-wordpress-rfi-vulnerability-added-to-cisa-kev-catalog","14e25773-10ca-4aea-9197-2394ca42f480","Actively Exploited WordPress RFI Vulnerability Added to CISA KEV Catalog","CVE-2026-87902, a Remote File Inclusion (RFI) vulnerability in WordPress Core, has been added to CISA's Known Exploited Vulnerabilities Catalog after evidence of active exploitation in the wild. RFI vulnerabilities allow attackers to inject and execute malicious remote code on a server, potentially leading to full system compromise, data exfiltration, or ransomware deployment. This addition underscores the critical need for organizations to treat KEV-listed vulnerabilities as the highest remediation priority, not just as compliance checkboxes. The fact that this vulnerability is being actively exploited means every day without patching represents direct, measurable risk to internet-facing WordPress assets.","**Immediate actions:**\n- Apply the latest WordPress Core security patch immediately, prioritizing all publicly accessible WordPress installations.\n- Run an authenticated vulnerability scan against all internet-facing assets to identify unpatched instances of CVE-2026-87902.\n- Temporarily restrict external access to vulnerable WordPress instances via WAF rules or IP allowlisting until patching is complete.\n\n**Long-term improvements:**\n- Establish a formal SLA-driven patching process that mandates remediation of CISA KEV vulnerabilities within 24–72 hours of catalog addition.\n- Maintain a continuously updated inventory of all internet-facing assets, including CMS platforms and their version numbers, to enable rapid impact assessment.\n- Implement a Web Application Firewall (WAF) with up-to-date rulesets to detect and block RFI exploit attempts as a defense-in-depth layer.\n\n**Detection measures:**\n- Configure centralized logging to alert on anomalous outbound HTTP\u002FS requests from web servers, which may indicate successful RFI exploitation.\n- Subscribe to CISA KEV Catalog alerts and integrate new entries directly into your vulnerability management platform for automated ticket creation.\n- Conduct regular threat hunting exercises focused on indicators of compromise associated with RFI attack patterns on web-facing infrastructure.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","CISA BOD 26-04: Reducing the Significant Risk of Known Exploited Vulnerabilities","GDPR Article 32: Security of Processing (timely remediation of known risks)","ISO 27001 A.12.6.1: Management of Technical Vulnerabilities","ITIL 4: Change Enablement \u002F Emergency Change Process","published","2026-09-25T20:23:06.075962+00:00","2026-09-25T20:23:05.765+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F09\u002F25\u002Fcisa-adds-one-known-exploited-vulnerability-catalog","cisa-adds-one-known-exploited-vulnerability-to-catalog-a5a9e1","CISA Adds One Known Exploited Vulnerability to Catalog",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]