Nacsa.My Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908
Article Content
- •CVE-2026-48907 and CVE-2026-48908 are critical RCE vulnerabilities in Joomla extensions.
- •Both vulnerabilities allow unauthenticated attackers to execute arbitrary PHP code remotely.
- •Immediate updates or patches are recommended to mitigate risks of data theft and server compromise.
Two critical vulnerabilities affecting Joomla extensions have been reported: CVE-2026-48907 in the Joomla Content Editor (JCE) and CVE-2026-48908 in the SP Page Builder. Both vulnerabilities allow unauthenticated remote attackers to execute arbitrary PHP code on affected servers, leading to potential full server compromise. CVE-2026-48907 affects JCE versions 1.0.0 to 2.9.99.4, while CVE-2026-48908 impacts SP Page Builder versions 1.0.0 to 6.6.1. Successful exploitation can result in data theft, defacement, and persistent unauthorized access. The vulnerabilities have been assigned a critical risk level with a CVSS score of 10.0. Administrators are urged to update to the latest versions or apply available patches immediately. Both vulnerabilities have been added to the CISA KEV list due to active exploitation. Affected entities are advised to report incidents to NC4 for coordination and intelligence sharing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-48907 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…