Critical WordPress Flaw and Active Exploits: Update Your Systems Now

by The Creator | Sep 26, 2026

A critical WordPress vulnerability (CVE-2026-87902, CVSS 9.2) is actively being exploited and has been added to CISA's Known Exploited Vulnerabilities catalog. Small business owners running WordPress sites must apply the latest wordpress vulnerability patch immediately, along with updates to SharePoint, RouterOS, and the Elementor plugin to block unauthenticated attackers from executing code on their systems.

September 26, 2026, Today's cybersecurity update focuses on four urgent threats that small business owners need to address immediately.

CISA has added a critical WordPress Core vulnerability (CVE-2026-87902, CVSS 9.2) to its Known Exploited Vulnerabilities catalog. This flaw allows unauthenticated attackers to execute arbitrary code on WordPress sites. All WordPress site owners should update to the latest version immediately.

Two additional vulnerabilities are being actively exploited in the wild: a code injection flaw in Microsoft SharePoint (CVE-2026-65660, CVSS 8.8) and a security hole in MikroTik RouterOS. Both allow remote code execution without authentication. Organizations using these products must apply patches immediately.

A high-severity cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder WordPress plugin (CVSS 8.8) allows attackers to create rogue administrator accounts and take full control of websites if an administrator clicks a malicious link. Businesses using Elementor should update to the latest version and exercise caution with unsolicited links.

Kiteworks (formerly Accellion) issued an unprecedented warning to customers, requesting a precautionary nine-hour system shutdown over the weekend after receiving credible threat intelligence from federal authorities about an imminent cyberattack targeting their systems. Kiteworks customers should follow the company's security guidance closely.

These incidents underscore the critical importance of timely security updates and patch management for small businesses. Attackers are actively exploiting known vulnerabilities, and businesses that delay updates put themselves at significant risk.

Which wordpress vulnerability patch addresses the CISA alert?

CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities list on September 26, 2026, because attackers are actively exploiting this WordPress Core flaw to execute arbitrary code without authentication. Three other critical flaws are also under active attack: CVE-2026-65660 (Microsoft SharePoint RCE, CVSS 8.8), a MikroTik RouterOS vulnerability, and an Elementor CSRF flaw (CVSS 8.8) that allows attackers to create rogue admin accounts. For SMBs, the immediate action is to check your WordPress installation version and apply the latest update through the dashboard. If you use SharePoint or Elementor, contact your IT provider to schedule patches within 48 hours. Delay creates downtime and breach risk.

Key takeaways

  • WordPress Core CVE-2026-87902 allows unauthenticated code execution. Update all WordPress sites today via the dashboard.
  • Elementor plugin CSRF flaw enables attackers to create admin accounts. Update the plugin and warn staff about suspicious links.
  • SharePoint (CVE-2026-65660) and MikroTik RouterOS also under active attack. Prioritize patches for internet-facing systems.
  • Kiteworks customers received warning of imminent attack and initiated emergency shutdown. Monitor vendor security bulletins for your tools.

Frequently asked questions

How do I apply a wordpress vulnerability patch to my site?

Log in to your WordPress dashboard, navigate to Updates, and click Update Now next to WordPress Core. This typically takes 5-10 minutes and requires no technical expertise. If you use a managed WordPress host, patches often apply automatically. Always back up your site before updating.

What happens if I don't patch the wordpress vulnerability?

Attackers can run malicious code on your site, steal customer data, install ransomware, or take the site offline. This results in downtime, liability for data loss, and customer trust damage. CISA explicitly listed this flaw because active attacks are ongoing.

Do I need to patch if I have a WordPress plugin firewall?

A firewall adds a layer of protection but does not replace the official patch. Patch your WordPress installation first. Firewalls can fail under sustained attack or during zero-day windows. Patches fix the root cause.

How do I know which version of WordPress I'm running?

Log in to your WordPress dashboard and check the bottom right corner of the screen or go to Dashboard > Updates. You'll see your current version number. Compare it to the latest version listed on WordPress.org or contact your hosting provider.

Sources

Keep reading