Breakglass
Incidents
← IncidentsConnecting…
INC-0009·Mercy Valley Community Hospital·Public websiteReplay of a real KEV entrySimulated hospital

WordPress Core matched the public website, but nothing is hitting the risky paths: no change, watch armed

CVE-2026-87902, WordPress Core (CISA KEV). The code path is exposed, but nothing is hitting it. Breakglass changes nothing and leaves a watch behind.

– NO ACTION · WATCH ARMED
234688:08:44
no clock: no change made
federal due window: 3 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
✓The code reaches the flawed partSemgrep · SEMGREP CE · config
targets/edge-config/nginx.conf:37 Every PHP entry point is proxied from the internet to `http://wordpress:80`.
location ~ \.php$ {
        proxy_pass http://wordpress:80;
    }
rule bg-edge-php-entrypoints-exposed
Third-party product with no source in scope: Semgrep checks the reverse-proxy config for internet exposure of the affected path.
✕No traffic on that routeClickHouse · CLICKHOUSE CLOUD
0 requests on 3 candidate routes in the last 5 min, 0 unblocked
The agent's query
SELECT route_id, client_kind, count() AS total, countIf(blocked = 0) AS unblocked
FROM bg.edge_requests
WHERE site = 'managed' AND route_id IN ('site.xmlrpc', 'site.comments', 'site.oembed')
  AND ts >= now() - INTERVAL 300 SECOND
GROUP BY route_id, client_kind
– ONE FACTOR MISSING: NO CHANGEStatic evidence alone, or traffic alone, never triggers a change.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /site/xmlrpc.php, per 10 s
1004:28:2004:29:300
patient journeys passing, % (one every 30 s; held between runs)
100004:28:2004:29:30100%

Verification runs after a control is applied: zero unblocked requests on the risky route, and a scripted patient still signs in and books.

fig. 5Agent trace · hosted and run in Guild 01a10a52-e60d-351a-0000-9bdcb9f5cf3eopen in Guild ↗Guild's record →every tool call, logged
0100:00.0triggeradvisory.insert CVE-2026-87902 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match website · WordPress Core 6.8.2
0300:00.6triggerguild.session Guild session 01a10a52-e60d-351a-0000-9bdcb9f5cf3e started for code~breakglass-decision
0700:03.8guildguild.llm model call · gpt-4.1 (openai)
0800:04.8guildguild.llm model asked for breakglass_incident_context, breakglass_inventory_match
0900:05.0guildguild.tool tool call (incident_id=INC-0009)
1000:05.2guildguild.tool tool call (incident_id=INC-0009)
1100:06.2guildguild.llm model call · gpt-4.1 (openai)
1200:07.0guildguild.llm model asked for breakglass_clickhouse_route_traffic, breakglass_semgrep_reachability
1300:07.3guildguild.tool tool call (incident_id=INC-0009)
1400:07.5guildguild.tool tool call (incident_id=INC-0009)
0400:07.8toolsemgrep.config reachable · 1 finding(s) · routes site.xmlrpc, site.comments, site.oembed
0500:08.4toolclickhouse.route_traffic 0 requests on 3 candidate route(s) in 5 min · hostile on none
1500:09.1guildguild.llm model call · gpt-4.1 (openai)
1600:10.0guildguild.llm model asked for breakglass_close_without_change
1700:10.3guildguild.tool tool call (incident_id=INC-0009, reason=Although Semgrep confirms the nginx config exposes all candi)
0600:10.9stateevidence.two_factor no change: Although Semgrep confirms the nginx config exposes all candidate routes linked to the WordPress remote file inclusion flaw, ClickHouse shows no live traffic on any of these routes. Both factors are not present, so no action is required.
1800:11.3guildguild.llm model call · gpt-4.1 (openai)
1900:12.2guildguild.reply Closed without a change.
2000:12.4guildguild.done Closed without a change.
Watch retiredAny unblocked non-patient request to /site/xmlrpc.php reopens INC-0009W-0009

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 0 hostile requests per 10 s to /site/xmlrpc.php.

TimeWhat happenedSource
04:29:26 UTCAdvisory ingested
CVE-2026-87902 entered the advisory stream (replay of a real KEV entry)
MongoDB
04:29:35 UTCEvidence query
0 requests on 3 candidate route(s) in 5 min · hostile on none
ClickHouse

fig. 0 The advisory

What the government's list says
CVE-2026-87902Replay of a real KEV entry
WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Added to KEV
Sep 25, 2026
Federal due date
Sep 28, 2026 (3 days after listing)
EPSS
45.5% chance of exploitation in 30 days · 98.8th percentile (2026-10-04)
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

UTC
Advisory ingested
04:29:26 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
04:29:27 UTC
Closed
04:29:37 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.