WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH

CISA Adds One Known Exploited security flaw to Catalog

System with various wires managing access to centralized resource of server in data center
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities .

CVE-2026-87902 (the public catalogue number for a specific software flaw) WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

Sources & evidence