KEV agrega CVE-2026-87902 — WordPress / Core
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
- cve_id
- CVE-2026-87902
- vendor_product
- WordPress / Core
KEV agrega CVE-2026-67279 — MikroTik / RouterOS
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
KEV agrega CVE-2026-65660 — Microsoft / SharePoint
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.