Skip to content
Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908

Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908

First seen 4 Aug 2026, 14:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 5, 2026 at 14:09 UTC
  • CVE-2026-48907 and CVE-2026-48908 are critical RCE vulnerabilities in Joomla extensions.
  • Both vulnerabilities allow unauthenticated attackers to execute arbitrary PHP code remotely.
  • Immediate updates or patches are recommended to mitigate risks of data theft and server compromise.

Two critical vulnerabilities affecting Joomla extensions have been reported: CVE-2026-48907 in the Joomla Content Editor (JCE) and CVE-2026-48908 in the SP Page Builder. Both vulnerabilities allow unauthenticated remote attackers to execute arbitrary PHP code on affected servers, leading to potential full server compromise. CVE-2026-48907 affects JCE versions 1.0.0 to 2.9.99.4, while CVE-2026-48908 impacts SP Page Builder versions 1.0.0 to 6.6.1. Successful exploitation can result in data theft, defacement, and persistent unauthorized access. The vulnerabilities have been assigned a critical risk level with a CVSS score of 10.0. Administrators are urged to update to the latest versions or apply available patches immediately. Both vulnerabilities have been added to the CISA KEV list due to active exploitation. Affected entities are advised to report incidents to NC4 for coordination and intelligence sharing.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-06-05
CVE-2026-48907 published
A critical improper access control vulnerability in JCE was disclosed, allowing RCE.
Nacsa.My
2026-06-10
First public PoC for CVE-2026-48907
A proof of concept for exploiting the JCE vulnerability was made public, increasing risk.
Nacsa.My
2026-06-16
CVE-2026-48907 added to CISA KEV
CISA added CVE-2026-48907 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Nacsa.My
2026-06-20
CVE-2026-48908 published
A critical improper access control vulnerability in SP Page Builder was disclosed, allowing RCE.
Nacsa.My
2026-06-22
First public PoC for CVE-2026-48908
A proof of concept for exploiting the SP Page Builder vulnerability was released.
Nacsa.My
2026-07-07
CVE-2026-48908 added to CISA KEV
CISA included CVE-2026-48908 in its Known Exploited Vulnerabilities list due to ongoing exploitation.
Nacsa.My
2026-08-04
Advisory issued for CVE-2026-48907 and CVE-2026-48908
NACSA issued advisories urging immediate updates to affected Joomla extensions to mitigate risks.
Nacsa.My

More articles in this cluster (4)

Following this threat?

Track CVE-2026-48907 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed