Skip to content

Weekly roundup

Open-source business platforms, week 39 of 2026: exploited WordPress flaw leads 17 CVEs

Critical 9.4 KEV Vendor: Open-source business platforms 17 advisories in scope Published

Open-source business platforms, week 39 2026: 17 CVEs in scope — 1 critical, 8 high, 8 medium. CVE-2026-87902, a WordPress page-template flaw that can lead to RCE, is actively exploited and in CISA KEV. Patch WordPress and GLPI first.

The release at a glance

The week 39 roundup covers open-source business platform advisories published between 21 and 27 September 2026. In scope are 17 CVEs: one critical, eight high and eight medium. GLPI accounts for 13 of the 17, with WordPress, Server, Frappe Framework and ERPNext accounting for one each. The release is led by CVE-2026-87902, a WordPress page-template flaw that can lead to remote code execution under certain server and theme conditions. CISA added it to KEV on 25 September 2026, and ENISA's EUVD records exploitation since 23 September 2026. CISA's due date for KEV remediation is 28 September 2026.

What matters most

WordPress. CVE-2026-87902 is the priority. An unauthenticated attacker can make page-template resolution include a chosen readable PHP file outside the active theme; if server and theme pre-conditions align, this leads to remote code execution. It is fixed in WordPress 7.1.2, with backported fixes listed from 4.7.37 through 7.0.6. This is the only issue in this week's scope known to be actively exploited, as recorded by CISA KEV and ENISA EUVD. It has its own advisory page on this site.

GLPI. Thirteen items are in scope, mostly high. CVE-2026-48482 is the critical one: a form administrator can use a crafted Form import to write a file outside the custom-asset directory and invoke it remotely; fixed in 11.0.8. CVE-2026-47679 allows any logged-in user to request deletion of an attacker-selected server file; fixed in 10.0.26 and 11.0.8. CVE-2026-53625 lets a technician change another user's authentication method through the API, which can enable account takeover under legacy API REST or SSO configurations; fixed in 10.0.26 and 11.0.8. CVE-2026-53629 is SQL injection in the history tab for users with READ rights on logs; fixed in 10.0.26 and 11.0.8. CVE-2026-55214 is stored XSS in supplier website fields, CVE-2026-53610 is reflected XSS in dashboards, and CVE-2026-49470 is missing rate limiting on TOTP verification; these are fixed in 11.0.8. Several of these GLPI flaws also have their own advisory pages on this site.

Patch in this order

  1. WordPress: apply 7.1.2, or the appropriate backported release listed in the advisory, for CVE-2026-87902. It is actively exploited and in CISA KEV; CISA's due date is 28 September 2026. Identify internet-exposed WordPress instances first.
  1. GLPI installations before 11.0.8: update to 11.0.8. This addresses CVE-2026-48482, CVE-2026-47679, CVE-2026-53625, CVE-2026-53629, CVE-2026-55214, CVE-2026-53610, CVE-2026-49470, CVE-2026-53626, CVE-2026-53627 and CVE-2026-53628.
  1. GLPI 10.0 installations before 10.0.26: update to 10.0.26. This addresses CVE-2026-47679, CVE-2026-53625, CVE-2026-53629, and CVE-2026-53628.
  1. Server 32.0.0 to 34.0.0: no fixed version or workaround is stated for CVE-2026-77165 in the CVE record.
  1. For the remaining medium-severity advisories affecting Frappe Framework, ERPNext and GLPI, no fixed versions are stated in this roundup; follow the vendor advisories as they are released.

Beyond the patch

Next month, reuse the same discipline: inventory your internet-facing WordPress and GLPI instances, then patch the exploited item before the long tail. Managed Detection & Response is the fit where exploitation is already active, and Implementation & Assessment Services can test and harden a public WordPress or GLPI deployment ahead of the next release.

Every advisory in this release

IDProductSeverity
CVE-2026-87902WordPressHigh 8.1 KEVAdvisory →
CVE-2026-48482glpiCritical 9.4Advisory →
CVE-2026-55214glpiHigh 8.5Advisory →
CVE-2026-47679glpiHigh 8.5Advisory →
CVE-2026-49470glpiHigh 7.7Advisory →
CVE-2026-53610glpiHigh 7.5Advisory →
CVE-2026-53625glpiHigh 7.5Advisory →
CVE-2026-53629glpiHigh 7.1Advisory →
CVE-2026-53626glpiHigh 7.1Advisory →
CVE-2026-77165ServerMedium 6.5
CVE-2026-53627glpiMedium 6.0Advisory →
CVE-2026-53628glpiMedium 5.9Advisory →
GHSA-hxfh-hh23-fvchFrappe FrameworkMedium 6.1
CVE-2026-45801glpiMedium 5.3
CVE-2026-55217glpiMedium 5.3
CVE-2026-96672ERPNextMedium 5.3
CVE-2026-49469glpiMedium 4.6

References

Exploit and analysis

CVE

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.