logo

Critical Joomla JCE Vulnerability Under Active Exploitation

ID: 145e7ed6-6d8d-55f2-b939-d6eec7fee521

STIX ID: report--145e7ed6-6d8d-55f2-b939-d6eec7fee521

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-21

...
...

A critical unauthenticated remote code execution vulnerability in the Joomla Content Editor (JCE), CVE-2026-48907 (CVSS 10.0), affects JCE versions below 2.9.99.6 and is being actively exploited: attackers import rogue editor profiles to upload PHP web shells, automated scanning campaigns have targeted numerous Joomla sites with hundreds reportedly compromised, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 16, 2026; site owners are urged to update to JCE 2.9.99.6 and check for unauthorized profiles and suspicious PHP files in writable directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.