SharePoint Server CVE-2026-65660 and WordPress CVE-2026-87902 are now exploited: check the August SharePoint update and WordPress 7.1.2
EditorialBy TrustList Editorial
On 25 September 2026 CISA listed two more flaws as exploited: a SharePoint Server code-injection flaw fixed in Microsoft’s August 2026 updates, and a WordPress core file-inclusion flaw fixed in 7.1.2 on 22 September. Confirm both updates are installed.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Collaboration Software
- +1 more
About SharePoint Server CVE-2026-65660 and WordPress CVE-2026-87902 are now exploited: check the August SharePoint update and WordPress 7.1.2
SharePoint Server CVE-2026-65660 and WordPress CVE-2026-87902 are now exploited: check the August SharePoint update and WordPress 7.1.2
2 October 2026 — The US Cybersecurity and Infrastructure Security Agency added two widely used business platforms to its Known Exploited Vulnerabilities catalogue on 25 September 2026, giving US federal agencies until 28 September to act and flagging both for forensic triage. Both already have fixes, which makes the question for every other organisation simple: were they installed?
Not yet independently verified. No independent report of either exploitation was checked, and neither Microsoft nor WordPress has described the attacks. Microsoft’s own record still shows its original “exploitation less likely” assessment beside the revision that reports attacks. We will update this when it can be confirmed, and remove this note.
SharePoint Server: CVE-2026-65660
- What it is: a code-injection flaw in SharePoint Server that "allows an authorized attacker to execute code over a network". Microsoft rates it Important, 8.8. It needs a signed-in user, but in many organisations every employee can sign in to SharePoint.
- Fixed: in Microsoft's August 2026 security updates, released on 11 August: KB5002893 for SharePoint Server Subscription Edition, KB5002894 for SharePoint Server 2019 and KB5002905 for SharePoint Enterprise Server 2016.
- What changed: Microsoft revised the entry on 25 September 2026: "As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability."
- Not affected: SharePoint Online in Microsoft 365, which Microsoft patches itself.
WordPress: CVE-2026-87902
- What it is: WordPress.org's release post of 22 September says "an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories", which can lead to remote code execution depending on the server and the theme.
- Fixed: in WordPress 7.1.2, with the fix back-ported to every supported branch down to 4.7. Most sites update minor releases automatically, but sites where automatic updates are disabled, or managed by an agency on a fixed schedule, may not have it.
What to do
- SharePoint Server: confirm the August 2026 update (and any later cumulative update) is installed on every farm server, including test and disaster-recovery farms; review IIS and SharePoint logs since August for unusual page or web-part changes and new files in the layouts folders; limit who can create and edit pages.
- WordPress: check the version on every site you own or that an agency runs for you, including staging and old campaign sites; update to 7.1.2 or the patched release of your branch; look for PHP files that should not be there and for unexpected administrator accounts.
- Hosting and managed-service providers should be asked in writing when each update was applied.
Sources
- Microsoft Security Response Center: CVE-2026-65660, Microsoft SharePoint Server Remote Code Execution Vulnerability (revised 25 September 2026) — 25 September 2026
- WordPress.org: WordPress 7.1.2 Security Release — 22 September 2026
- CISA Known Exploited Vulnerabilities catalogue: CVE-2026-65660 and CVE-2026-87902 (added 25 September 2026) — 25 September 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Collaboration Software
- Web Development
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.