Threat actors are actively exploiting CVE-2026-87902, a critical WordPress vulnerability, to execute arbitrary code on affected sites. The attacks have progressed from reconnaissance to writing malicious files that execute shell commands.
Security researchers have detected active exploitation of CVE-2026-87902, a critical vulnerability affecting WordPress installations. Attackers have moved beyond initial probing of vulnerable sites to deploying functional exploits that write files to disk.
The attack chain works by writing files to the server that execute shell commands when accessed. This enables attackers to gain code execution capabilities on compromised WordPress instances, potentially leading to full site compromise.
The vulnerability affects a significant portion of WordPress deployments. Organizations running unpatched WordPress installations remain at immediate risk of compromise.
Recommended actions:
- Update WordPress to the latest patched version immediately
- Review server logs for suspicious file writes and web requests
- Audit user accounts and access credentials on affected systems
- Consider implementing Web Application Firewall rules to block exploitation attempts
- Scan WordPress installations for shells or malicious files already written to disk
The transition from reconnaissance to active exploitation underscores the urgency of patching. Historical data shows that once attackers begin weaponizing vulnerabilities, exploitation rates typically accelerate rapidly across the internet.
WordPress powers approximately 43% of all websites globally, making vulnerabilities in the platform a high-priority target for threat actors. Users who cannot immediately patch should consider taking affected sites offline or restricting access pending remediation.
Security teams should treat this as a critical incident requiring immediate response. The ability to execute arbitrary code allows attackers to install backdoors, steal data, deface content, or pivot to other systems on the network.
Rising concerns over AI safety and autonomous agents are accelerating investment in next-generation security platforms. Startups building AI-native defenses are attracting unprecedented capital.
Hackers are leveraging customizable artificial intelligence models to scale malicious campaigns with unprecedented efficiency. The trend marks a significant shift in how cybercriminals operate.
The FBI is investigating claims that hackers breached its systems and stole personal information from thousands of current and former employees. The bureau confirmed the breach investigation in a statement Wednesday.
The National Highway Traffic Safety Administration is investigating comma.ai, an autonomous driving software company, following multiple crashes and deaths involving vehicles using its devices. Federal investigators have documented at least 5 incidents where comma.ai-equipped cars struck slow or stopped vehicles.