WordPress Core matched the public website, but nothing is hitting the risky paths: no change, watch armed
CVE-2026-87902, WordPress Core (CISA KEV). The code path is exposed, but nothing is hitting it. Breakglass changes nothing and leaves a watch behind.
fig. 1 Evidence · two factors before any action
Could it happen here? Is it happening?fig. 4 Verification · risk down, care up
ClickHouse, per 10 sVerification runs after a control is applied: zero unblocked requests on the risky route, and a scripted patient still signs in and books.
fig. 7 Attack timeline · ClickHouse
UTC · from the request log and this incident's eventsPeak 0 hostile requests per 10 s to /site/xmlrpc.php.
| Time | What happened | Source |
|---|---|---|
| 04:29:26 UTC | Advisory ingested CVE-2026-87902 entered the advisory stream (replay of a real KEV entry) | MongoDB |
| 04:29:35 UTC | Evidence query 0 requests on 3 candidate route(s) in 5 min · hostile on none | ClickHouse |
fig. 0 The advisory
What the government's list saysWordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
- Added to KEV
- Sep 25, 2026
- Federal due date
- Sep 28, 2026 (3 days after listing)
- EPSS
- 45.5% chance of exploitation in 30 days · 98.8th percentile (2026-10-04)
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Timeline
UTC- Advisory ingested
- 04:29:26 UTC
- Trigger
- Replay of a real KEV entry into the advisory stream
- Agent runtime
- Hosted and run in Guild · Guild's record · strategy: containment-first
- Opened
- 04:29:27 UTC
- Closed
- 04:29:37 UTC
Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.