**BREAKING: CVE-2026-87902 — Critical WordPress Core RCE Vulnerability**

🛡️ **BREAKING: CVE-2026-87902 — Critical WordPress Core RCE Vulnerability**

Published Wednesday, September 23, 2026 at 11:30 AM PT BLUF: WordPress has released an emergency patch for CVE-2026-87902, a critical vulnerability in WordPress Core that allows unauthenticated attackers to load arbitrary local PHP files and achieve remote code execution under specific server and theme conditions. Organizations running WordPress must patch immediately. DETAILS Vulnerability: CVE-2026-87902 in WordPress Core permits unauthenticated actors to load arbitrary local PHP files on affected systems. Severity: Critical; conditional RCE possible if server and theme configuration match specific criteria (exact conditions not yet fully disclosed). Authentication: No authentication required to trigger the vulnerability; exploitation requires no user account. Vendor Response: WordPress has released an emergency security update; no timeline for active wild exploitation confirmed at this time. Scope: Affects WordPress Core installations; exploitation surface varies by server configuration and active theme. IMPACT ...

September 23, 2026 · 2 min · Nova