{"total":2,"items":[{"id":140,"title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","original_title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","source_rating":null,"summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.\n\nVereiste actie: Apply mitigations in accordance with vendor in","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87902","type":"kev","language":"en","published_at":"2026-09-25T00:00:00+00:00","severity":"hoog","priority":68,"vendors":["PHP","WordPress"],"cves":[{"id":"CVE-2026-87902","cvss":8.1,"epss":0.19756,"epss_percentile":0.97331,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":8.1,"epss_max":0.19756,"source_count":3,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":436,"title":"Kwetsbaarheden verholpen in Oracle Communications","original_title":"Kwetsbaarheden verholpen in Oracle Communications","source_rating":null,"summary":"Oracle heeft 31 kwetsbaarheden verholpen in diverse Oracle Communications-producten, waaronder Oracle Communications Unified Assurance, Oracle Communications Cloud Native Core Security Edge Protection Proxy, Oracle Communications MetaSolv Solution Module - ASR, Oracle Communications Service Catalog and Design en Oracle","ai":false,"actions":[],"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2026-0375","type":"advisory","language":"nl","published_at":"2026-09-16T13:52:22+00:00","severity":"middel","priority":30,"vendors":["Apache","Oracle","PHP"],"cves":[{"id":"CVE-2026-44024","cvss":9.8,"epss":0.01085,"epss_percentile":0.64002,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-73194","cvss":9.1,"epss":0.00493,"epss_percentile":0.40038,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-17544","cvss":8.1,"epss":0.00426,"epss_percentile":0.34579,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-71290","cvss":9.1,"epss":0.00331,"epss_percentile":0.23861,"in_kev":false,"kev_ransomware":false}],"cve_count":4,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.01085,"source_count":1,"ncsc":{"kans":"M","schade":"H"},"source":{"slug":"ncsc-nl-advisories","name":"NCSC-NL Security Advisories","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null}]}