Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The U.S. CISA Catalogs Additional Vulnerabilities to Address Increasing Threats in the Cybersecurity Landscape




The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a WordPress Core flaw with a high CVSS score, emphasizing the growing threats in the cybersecurity landscape. The vulnerabilities highlight the importance of timely patching and addressing known security flaws to prevent exploitation by hackers.

  • Microsoft SharePoint and Mikrotik RouterOS vulnerabilities were added to the Known Exploited Vulnerabilities (KEV) catalog.
  • A high-risk WordPress Core flaw (CVE-2026-87902, CVSS score 9.2) was also added, allowing remote code execution.
  • Experts emphasize the importance of timely patching and addressing known security flaws to prevent exploitation.
  • Federal agencies and private organizations are required to address identified vulnerabilities by the due date to protect their networks.
  • The KEV catalog addition highlights the evolving threat landscape and the need for increased vigilance in cybersecurity.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added several new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the growing threats in the cybersecurity landscape. Among the vulnerabilities added are those for Microsoft SharePoint and Mikrotik RouterOS, as well as a WordPress Core flaw tracked as CVE-2026-87902, which has a CVSS score of 9.2.

    The added vulnerabilities highlight the importance of timely patching and addressing known security flaws to prevent exploitation by hackers. The WordPress Core flaw, specifically, is a noteworthy addition, as it allows an unauthenticated attacker to make the get_page_template() function include a readable local PHP file outside the active theme directories. This vulnerability can lead to remote code execution under specific server and theme conditions, making it a high-risk vulnerability.

    Experts have long warned of the dangers of not addressing known security flaws in a timely manner. According to CISA's Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, federal agencies are required to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog. Private organizations are also advised to review the catalog and address the vulnerabilities in their infrastructure to prevent potential breaches.

    The addition of these vulnerabilities to the KEV catalog underscores the evolving threat landscape and the need for increased vigilance in the cybersecurity community. It also serves as a reminder to system administrators and cybersecurity professionals to prioritize patching and vulnerability management to ensure the security of their systems and networks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-US-CISA-Catalogs-Additional-Vulnerabilities-to-Address-Increasing-Threats-in-the-Cybersecurity-Landscape-ehn.shtml

  • https://securityaffairs.com/199790/security/u-s-cisa-adds-wordpress-flaw-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87902

  • https://www.cvedetails.com/cve/CVE-2026-87902/


  • Published: Sat Sep 26 03:28:30 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us