IONOS US incident

Critical Security Update: WordPress Core Vulnerability (CVE-2026-87902)

Minor Resolved View vendor source →

IONOS US experienced a minor incident on September 22, 2026 affecting Wordpress Hosting and Wordpress Pro, lasting 2d 10h. The incident has been resolved; the full update timeline is below.

Started
Sep 22, 2026, 09:37 PM UTC
Resolved
Sep 25, 2026, 07:56 AM UTC
Duration
2d 10h
Detected by Pingoru
Sep 22, 2026, 09:37 PM UTC

Affected components

Wordpress HostingWordpress Pro

Update timeline

  1. identified Sep 22, 2026, 09:37 PM UTC

    A critical security vulnerability affects WordPress versions 4.7.0 through 7.1.1, which can allow remote code execution under specific conditions. Managed WordPress Customers No action needed:IONOS is automatically patching your site and deploying proactive security measures Self-Managed WordPress Customers Action required: Update WordPress immediately to the latest version More updates will be posted here as new information becomes available.

  2. resolved Sep 25, 2026, 07:56 AM UTC

    The issue has been resolved.