Critical Joomla JCE Vulnerability Under Active Exploitation
ID: a2b5fccd-25a6-5da5-86c1-b5905afe7ab8
STIX ID: report--a2b5fccd-25a6-5da5-86c1-b5905afe7ab8
Feed Name: ThreatCluster
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2026-48907, CVSS 10.0) in the Joomla Content Editor (JCE < 2.9.99.6) is being actively exploited; CISA added it to the KEV catalog on 2026-06-16. Attackers import malicious editor profiles to upload PHP web shells, automated scanning campaigns have compromised hundreds of Joomla sites, and site owners are urged to update to JCE 2.9.99.6 and search for unauthorized profiles and suspicious PHP files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
