The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added a maximum-severity flaw affecting a highly popular Joomla extension—the Joomla Content Editor (JCE)—to its Known Exploited Vulnerabilities catalog. Tracked as a perfect 10/10 risk score, the bug allows unauthenticated attackers to bypass access controls, create rogue editor profiles, and execute malicious PHP backend code. Security firms noted that the vulnerability is actively being weaponized globally to drop web shells and establish server backdoors, making immediate patching a critical requirement for anyone managing a Joomla environment.
This vulnerability is being tracked as CVE-2026-48907.
Source: https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html
Leave a Reply