logo

Critical Joomla JCE Vulnerability Under Active Exploitation

ID: a2b5fccd-25a6-5da5-86c1-b5905afe7ab8

STIX ID: report--a2b5fccd-25a6-5da5-86c1-b5905afe7ab8

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-22

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2026-48907, CVSS 10.0) in the Joomla Content Editor (JCE < 2.9.99.6) is being actively exploited; CISA added it to the KEV catalog on 2026-06-16. Attackers import malicious editor profiles to upload PHP web shells, automated scanning campaigns have compromised hundreds of Joomla sites, and site owners are urged to update to JCE 2.9.99.6 and search for unauthorized profiles and suspicious PHP files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.