Hackers start exploiting critical WordPress flaw for code execution

2026-09-23T19:23:22Z•9fe76430a67d23dd9afd686b9b4aa662ed04a4e5fea6a17d19bc1abb3a3f2b1c
CVE-2026-87902AI-assisted malwareCheck PointF5 BIG-IPKubernetesOracle PeopleSoftVeloCloud OrchestratorWordPressZyxelactive exploitationcloud privilege escalationcredential theftcritical vulnerabilitiesdata theftgovernment targetsransomwareremote code executionweb skimmingzero-day

What happened

BleepingComputer reports widespread active exploitation of critical and zero-day vulnerabilities affecting WordPress, F5 BIG-IP APM, Check Point Security Management Server, Arista VeloCloud Orchestrator, Zyxel switches, and potentially Oracle PeopleSoft. Reported activity includes remote code execution, webshell or command execution through written files, theft of government and payment-card data, ransomware, malicious skimmers, cloud privilege escalation through Kubernetes Config Connector, and AI-assisted malware operations. Organizations should prioritize emergency vendor patches, exposure’

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9fe76430a67d23dd9afd686b9b4aa662ed04a4e5fea6a17d19bc1abb3a3f2b1c
Enrichment time
2026-09-23T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers start exploiting critical WordPress flaw for code execution · Baitaphish