Serial number:AV26-952
Date:September 23, 2026
Updated: September 25, 2026
As of September 22, 2026, WordPress is affected by a vulnerability in the following product:
- WordPress
- Prior to 7.1.2
Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild.
Update 1
On September 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87902 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.


