Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908

Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908

First seen 4 Aug 2026, 14:23 UTC Nacsa.Myapp.opencve.iogithub.com 90% similarity 89.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities affecting Joomla extensions have been reported: CVE-2026-48907 in the Joomla Content Editor (JCE) and CVE-2026-48908 in the SP Page Builder. Both vulnerabilities allow unauthenticated remote attackers to execute arbitrary PHP code on affected servers, leading to potential full server compromise. CVE-2026-48907 affects JCE versions 1.0.0 to 2.9.99.4, while CVE-2026-48908 impacts SP Page Builder versions 1.0.0 to 6.6.1. Successful exploitation can result in data theft, defacement, and persistent unauthorized access. The vulnerabilities have been assigned a critical risk level with a CVSS score of 10.0. Administrators are urged to update to the latest versions or apply available patches immediately. Both vulnerabilities have been added to the CISA KEV list due to active exploitation. Affected entities are advised to report incidents to NC4 for coordination and intelligence sharing.

Key Points: • CVE-2026-48907 and CVE-2026-48908 are critical RCE vulnerabilities in Joomla extensions. • Both vulnerabilities allow unauthenticated attackers to execute arbitrary PHP code remotely. • Immediate updates or patches are recommended to mitigate risks of data theft and server compromise.

ThreatCluster AI How this analysis works

Timeline

2026-06-05
CVE-2026-48907 published
A critical improper access control vulnerability in JCE was disclosed, allowing RCE.
Nacsa.My
2026-06-10
First public PoC for CVE-2026-48907
A proof of concept for exploiting the JCE vulnerability was made public, increasing risk.
Nacsa.My
2026-06-16
CVE-2026-48907 added to CISA KEV
CISA added CVE-2026-48907 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Nacsa.My
2026-06-20
CVE-2026-48908 published
A critical improper access control vulnerability in SP Page Builder was disclosed, allowing RCE.
Nacsa.My
2026-06-22
First public PoC for CVE-2026-48908
A proof of concept for exploiting the SP Page Builder vulnerability was released.
Nacsa.My
2026-07-07
CVE-2026-48908 added to CISA KEV
CISA included CVE-2026-48908 in its Known Exploited Vulnerabilities list due to ongoing exploitation.
Nacsa.My
2026-08-04
Advisory issued for CVE-2026-48907 and CVE-2026-48908
NACSA issued advisories urging immediate updates to affected Joomla extensions to mitigate risks.
Nacsa.My

Community

Browse all →

Tracked Entities in This Story