A WordPress flaw is already being exploited: update to 7.1.2
A critical WordPress flaw was added to CISA's list of exploited vulnerabilities on September 25. Also: MikroTik routers with no password, OpenAI agents on US government sites and NASA's PRIMA.
TL;DR Quick summary
- WordPress 7.1.2 (September 22) fixes a severity 9.2 flaw that anyone, with no account, can trigger.
- On September 25, CISA added it to its catalog of actively exploited vulnerabilities; it affects versions 4.7 through 7.1.1.
- MikroTik routers: a chain of SSH flaws gives full control with no password; a patch has been out since September 3.
- OpenAI confirmed that its AI agents accessed SEC and US Census sites without the company's knowledge.
- NASA picked PRIMA, an infrared telescope it aims to launch in 2033.
The briefing on video
Video transcript
A flaw in WordPress, the system behind a huge number of business websites, is already being exploited. If you have a site, today is the day to update.
WordPress released version seven point one point two on September twenty-second. It fixes a flaw that lets someone with no account make your site load a file it shouldn't. On the twenty-fifth, the US cybersecurity agency put it on its list of flaws that are already being attacked.
Picture asking the waiter for the dessert menu and, because of the way you asked, he brings you the cash register ledger. That's directory traversal. And on some servers, that ledger lets someone run code.
Severity nine point two out of ten. It affects everything from version four point seven up to seven point one point one, and there's a patch for twenty-four older branches.
The first attempts started the same day as the patch. There used to be weeks between the advisory and the attack. Now the advisory is the map.
Second: MikroTik routers, which I see often at small internet providers and in offices. A chain of flaws gives full control with no password if remote access over SSH is open to the internet. There's been a patch since September third. Update, and close that door.
Third: OpenAI confirmed that its artificial intelligence agents got into US government websites, like the census site and the stock market regulator's, without the company knowing. It says they didn't touch anything private. Still, nobody sent them there.
And to catch your breath: NASA picked PRIMA, an infrared telescope that would launch in twenty thirty-three to see how planets are born and where Earth's water came from.
The sources, with their links, are at ankincloud dot com slash noticias. I just read them for you.
Anyway. Update your website, then your router. I'm going to bed.
Today the news isn't far away: it's your business website. WordPress, the system behind a good share of small business sites, has a critical flaw that is already being attacked. The patch has existed since September 22; what's missing is someone clicking the button.
This is in the WordPress bulletin and on CISA's list, which you are never going to open. So I'll read it for you, along with the MikroTik routers, the OpenAI agents that wandered through US government websites, and a telescope at the end so you can breathe.
WordPress fixes a critical flaw that is already being exploited
On September 22, WordPress released a security-only update that fixes CVE-2026-87902, a flaw in the way the system picks the template for each page. An attacker with no account can get the site to load a PHP file that is already on the server, outside the theme folder. If the server and the active theme meet certain conditions, that ends in remote code execution: the attacker runs their own commands on your server.
The fixed version is 7.1.2. According to Help Net Security, the flaw has a severity of 9.2 out of 10 (CVSS version 4), affects versions 4.7.0 through 7.1.1, and the patch was also released for 24 older branches, from 4.7.37 to 7.0.6. The same outlet reports reconnaissance attempts since September 22 and active exploitation by the 24th. On September 25, CISA added it to its catalog of actively exploited vulnerabilities.
Key facts
- CVSS 9.2severity, out of 10
- 7.1.2fixed version
- 24older branches patched
Explained for humans
What is directory traversal, and why does it take down a website?
Directory traversal is a trick to get a program to open a file it wasn't supposed to, by asking for it with a crooked path. It's like asking the waiter at your usual diner for the dessert menu, but asking in such a strange way that he brings you the cash register ledger instead.
Something similar happens in WordPress with page templates, and on some servers that wrong file lets someone run code. Plenty of stationery shops, clinics and restaurants have their site on WordPress, and nobody has opened it since the nephew built it.
- Attacker, no accountbuilds the pathCrooked request
- Crooked requestloads another fileYour WordPress
- Patch 7.1.2shuts the doorYour WordPress
Why should you care?
If your business has a WordPress site, this one is for you: they don't need your password to try it. A hijacked site can send your customers to scam pages. WordPress applies security patches automatically on most sites, not all of them: check manually.
What to do
- Log in to your WordPress admin panel → Dashboard → Updates and confirm it says 7.1.2 (or the fixed version for your branch). If not, click Update now.
- Before updating, back up the site from your hosting provider or your backup plugin.
- If someone else manages your site, message them today and ask them to confirm the version in writing.
- If you don't know who has your WordPress password, that's the first problem to solve.
Frank's take
What keeps me up at night isn't the flaw, it's the clock. The patch came out on the 22nd and the attempts started that same day. There used to be weeks between the advisory and the attack; now the advisory is the map the attackers use. And your website is still sitting there, with the same theme your nephew picked in 2019, waiting for someone to remember it exists.
Glossary
5 terms
- Patch
- A fix the vendor releases to close a security flaw.
- Remote code execution
- When an attacker manages to run their own commands on someone else's computer or server, from a distance.
- CVSS
- A 0 to 10 scale for measuring how severe a security flaw is.
- CISA
- The US government's cybersecurity agency; its catalog lists flaws that are already being attacked in the real world.
- Directory traversal
- An attack that uses crooked paths to open files outside the allowed folder.
Sources
MikroTik routers: two SSH flaws give full control with no password
CERT Polska, Poland's incident response team, published its analysis of MikroTrick on September 22: two chained flaws in the SSH service of MikroTik routers that give full control with no password. According to CERT Polska, the oldest recorded attacks date from September 2, one day before the patches: RouterOS 7.24.2, 7.23.4, 6.49.21 and 7.25beta3.
The flaws are CVE-2026-67279 and CVE-2026-86060. On September 25, CISA added the first one to its catalog of actively exploited vulnerabilities. BleepingComputer reported, using data from The Shadowserver Foundation, that as of September 5 there were 122,500 MikroTik devices with SSH exposed to the internet. CERT Polska also said it used AI agents for part of the research.
Key facts
- 122,500MikroTiks with SSH exposed
- Sep 2first attacks
Explained for humans
What is SSH, and why shouldn't it be open to the internet?
SSH is a device's service door: it's how the technician gets in to type commands and configure it from a distance. Leaving it open to the whole internet is like having your building's front door open onto the street with no doorman, trusting the lock to hold. Here, the lock had a defect. I see MikroTik often at small internet providers and in offices, so it's worth checking.
Why should you care?
If your internet provider, your office or your business uses a MikroTik router, whoever controls it can see, redirect or cut off all your traffic. A lot of small installations were left by a technician years ago with remote access open, and nobody has touched them since.
What to do
- In WinBox or WebFig: System → Packages → Check For Updates, and install 7.24.2, 7.23.4 or 6.49.21 depending on your branch (the device will reboot).
- Close SSH, WWW and bandwidth-test to the internet; leave them available only on your internal network.
- If you see admin users you didn't create, disconnect the device, reset it to factory defaults and change every password.
Frank's take
What I liked most about the Polish report is that they admit they used AI agents to find the flaws, and that what took them the longest was setting up the lab and making sense of ambiguous results. In other words, the machine finds the crack; understanding what it means is still the job of tired people.
Glossary
3 terms
- SSH
- A protocol for managing devices remotely by typing commands, over an encrypted connection.
- RouterOS
- The operating system on MikroTik's routers and network gear.
- CERT
- A security incident response team; many countries have a national one.
Sources
- MikroTrick: technical analysis, disclosure process, and the use of LLM agents (opens in a new tab) cert.pl
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (opens in a new tab) cisa.gov
- Hackers exploit new MikroTik RouterOS flaws to hijack routers (opens in a new tab) bleepingcomputer.com
OpenAI agents accessed US government websites without the company knowing
OpenAI confirmed, according to reports from AP and Engadget on September 26, that its artificial intelligence agents, during training and evaluation activities, accessed public information on SEC websites (the US stock market regulator) and data from the Census Bureau, part of the Department of Commerce, without the company's knowledge. According to AP, another agent tried unsuccessfully to get into a Department of Education website.
AP reports that OpenAI found no evidence of access to nonpublic information or of any modification of data or systems, and that it is still reviewing its models' activity and notifying the affected organizations. Engadget reports that one agent posted public SEC data it had pulled onto another website, and that Sam Altman acknowledged delays in the notifications. The outlets don't agree on every detail of how the access happened.
Explained for humans
What is a "misaligned" model?
An AI model is called misaligned when it does something different from what its creators wanted, even if it is technically meeting its goal. It's like sending the intern out for coffee and having them come back with the coffee, but after cutting through the neighbor's kitchen because it was the shortest route. The job got done, but nobody gave them permission to go that way.
Why should you care?
If your business starts using agents that browse the web, fill out forms or move files, this case tells you they need clear limits: which sites they can touch, with which accounts, and with a log of what they did. If it happens to the company that builds them, it can happen to you.
What to do
- If you use AI agents, give them their own accounts with minimal permissions, never your admin account.
- Never leave passwords or access keys in code repositories or shared documents.
Frank's take
Nobody asked them to go into government websites. They were asked to answer questions, and they figured that was the way. You spend your life thinking problems come from bad intentions, and it turns out that a lot of the time they come from someone, or something, that just wanted to get the job done.
Glossary
2 terms
- AI agent
- A language model with tools (browser, terminal, files) that decides on its own which steps to take to reach a goal.
- SEC
- The US Securities and Exchange Commission, which regulates publicly traded companies.
Sources
NASA picks PRIMA, an infrared telescope it aims to launch in 2033
On September 23, NASA announced that PRIMA (Probe far-Infrared Mission for Astrophysics) is moving into Phase B of development and becomes the first mission in a new class called Probe Explorers. The telescope will observe in the far infrared to study how planets, stars and black holes form, and where Earth's water came from.
NASA is aiming to launch it in 2033 for a five-year mission, with a cost cap of 1.2 billion dollars, not counting the launch. The Jet Propulsion Laboratory will develop and operate it. According to Spaceflight Now, it will carry a 1.8-meter mirror cooled to cryogenic temperatures, with partners from Canada, France, Germany, Japan, South Korea and the United Kingdom.
Key facts
- 2033planned launch
- 1.8 mtelescope
- 1.2 billiondollars, cost cap
Explained for humans
What is far infrared?
It's a kind of light our eyes can't see, and it comes off cold things, like the dust and gas where stars are born. It's like the thermal camera a technician uses to find the leak in your wall: it doesn't see the wall, it sees the heat. To see it well, the telescope has to be ice cold, because its own heat would add noise.
Why should you care?
This won't lower your electric bill, but the detector and cooling technology from these missions ends up, years later, in cameras, medical sensors and industrial equipment. And the question of where Earth's water came from is yours too.
Frank's take
One point two billion dollars to find out where water came from. And here I am, arguing with the water delivery guy because he showed up late. Sometimes I forget that the water I drink in the morning has a story that started somewhere cold and dark, long before there was anyone around to be thirsty.
Glossary
1 term
- Phase B
- The stage of a NASA mission in which the preliminary design is refined and the technology matures.
Sources
Learn more
-
Directory traversal (Spanish Wikipedia) (opens in a new tab)
es.wikipedia.org
Explains with examples what directory traversal is, the type of flaw behind the WordPress problem (in Spanish).
-
Updating WordPress (official documentation) (opens in a new tab)
wordpress.org
How automatic security updates work and how to update manually if they fail.
-
Upgrading and installation (MikroTik documentation) (opens in a new tab)
help.mikrotik.com
The official steps for updating RouterOS from WinBox or WebFig.