Bleepingcomputer
Critical Joomla JCE Vulnerability Under Active Exploitation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and has a CVSS score of 10.0. Attackers exploit this vulnerability by importing rogue editor profiles to upload PHP web shells without any authentication. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on June 16, 2026, indicating active exploitation in the wild. Automated scanning campaigns have targeted numerous Joomla sites, with hundreds already compromised. Site owners are urged to update to the latest version immediately and check for signs of exploitation, including unauthorized profiles and suspicious PHP files in writable directories. The vulnerability has been confirmed by multiple sources, including security advisories and independent analyses.
Key Points: • CVE-2026-48907 allows unauthenticated remote code execution on Joomla sites using JCE. • CISA added this vulnerability to its KEV catalog on June 16, 2026, confirming active exploitation. • Site owners must update to JCE 2.9.99.6 and check for unauthorized profiles and web shells.