logo

CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw by Friday

ID: 1420bcfa-aa5b-58dc-937c-9b9f05ba893f

STIX ID: report--1420bcfa-aa5b-58dc-937c-9b9f05ba893f

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

...
...

**CVE-2026-48907** — a CVSS 10.0 improper-access-control vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin that permits unauthenticated attackers to create editor profiles, enable PHP uploads, and deploy webshells resulting in remote code execution — has been confirmed exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog with a federal patching deadline of June 20, 2026; the report outlines impact, detection commands, mitigation (patching/removal, disable plugin, block PHP execution), and incident response steps for compromised sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.