IONOS Status · History · Incident #140250

ACTIVE INCIDENT

Critical Security Update: WordPress Core Vulnerability (CVE-2026-87902)

Minor · Started Sep 22, 2026 · 5:37 PM

  • Duration

    Ongoing

  • Severity

    Minor

  • Detection lead

  • User reports

Summary

Critical Security Update: WordPress Core Vulnerability (CVE-2026-87902)

A critical security vulnerability affects WordPress versions 4.7.0 through 7.1.1, which can allow remote code execution under specific conditions. Managed WordPress Customers No action needed:IONOS is automatically patching your site and deploying proactive security measures Self-Managed WordPress Customers Action required: Update WordPress immediately to the latest version More updates will be posted here as new information becomes available.


  • Started

    Sep 22, 2026 · 5:37 PM

  • Status

    Identified

  • Duration

    Ongoing

  • Severity

    Minor

Event timeline

How this incident unfolded

  • Identified

    Sep 22 · 5:37 PM IONOS

    A critical security vulnerability affects WordPress versions 4.7.0 through 7.1.1, which can allow remote code execution under specific conditions. Managed WordPress Customers No action needed:IONOS is automatically patching your site and deploying proactive security measures Self-Managed WordPress Customers Action required: Update WordPress immediately to the latest version More updates will be posted here as new information becomes available.

Get alerted before the next IONOS outage.

Pulsetic catches degradations minutes before vendors acknowledge them.