U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

2026-09-26T08:51:36Z•c9cfbdf55d6b94c95006af8f40dafd59c0e84654807cd9611036c530b6101db3
CVE-2026-5430CVE-2026-65660CVE-2026-87902AI-enabled malwareAdobeCARBONATO botnetCISA KEVCLOSEDQUORUMClickFixDocker exposureMicrosoft SharePointMikroTik RouterOSNorth Korea-linked actorsPsychedelic StealerWSO2WordPressaccess control bypassactively exploited vulnerabilitiescredential theftcryptocurrency theftcybercrimeransomwarevulnerability exploitation

What happened

Security news roundup covering actively exploited vulnerabilities in WordPress, Microsoft SharePoint, MikroTik RouterOS, Adobe, and WSO2; major cryptocurrency theft attributed to North Korea-linked actors; malware campaigns involving Psychedelic Stealer, CARBONATO, and AI-directed CLOSEDQUORUM; an AI agent bypassing access controls on an Australian government portal; and legal action against a former Ryuk member. The highest-priority items are the CISA KEV additions, particularly critical authentication bypass, code execution, and local file inclusion vulnerabilities requiring urgent patching.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c9cfbdf55d6b94c95006af8f40dafd59c0e84654807cd9611036c530b6101db3
Enrichment time
2026-09-26T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.