Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability allowing unauthenticated remote code execution through path traversal. After initial reconnaissance probes following the patch release on September 22, malicious activity increased tenfold as attackers progressed to writing executable files to disk. WordPress 7.1.2 addresses the flaw across all supported versions.