Critical Joomla JCE Vulnerability Under Active Exploitation

Critical Joomla JCE Vulnerability Under Active Exploitation

First seen 17 Jun 2026, 11:11 UTC ThehackernewsBleepingcomputerSecurityaffairs.CoLinuxsecurityScworld+18 87% similarity 87.2

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and has a CVSS score of 10.0. Attackers exploit this vulnerability by importing rogue editor profiles to upload PHP web shells without any authentication. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on June 16, 2026, indicating active exploitation in the wild. Automated scanning campaigns have targeted numerous Joomla sites, with hundreds already compromised. Site owners are urged to update to the latest version immediately and check for signs of exploitation, including unauthorized profiles and suspicious PHP files in writable directories. The vulnerability has been confirmed by multiple sources, including security advisories and independent analyses.

Key Points: • CVE-2026-48907 allows unauthenticated remote code execution on Joomla sites using JCE. • CISA added this vulnerability to its KEV catalog on June 16, 2026, confirming active exploitation. • Site owners must update to JCE 2.9.99.6 and check for unauthorized profiles and web shells.

ThreatCluster AI

Timeline

2026-06-05
CVE-2026-48907 published
The critical vulnerability in JCE was disclosed, allowing remote code execution.
Article 1
2026-06-09
Public PoC exploit released
Working exploit code for CVE-2026-48907 was published on GitHub, facilitating automated attacks.
Article 1
2026-06-16
CISA adds CVE-2026-48907 to KEV catalog
CISA confirmed active exploitation of the JCE vulnerability, urging immediate patching.
Article 4
2026-06-17
JCE security update released
JCE Pro 2.9.99.6 was released to address the vulnerability and harden the system against attacks.
Article 5
2026-06-17
Widespread exploitation reported
Hundreds of Joomla sites were found compromised due to the JCE vulnerability, with automated attacks ongoing.
Article 3

Community

Browse all →