logo

CISA orders feds to patch max severity Joomla plugin flaw by Friday

ID: 74c9f73b-f400-517c-b38b-c4e06df16cc1

STIX ID: report--74c9f73b-f400-517c-b38b-c4e06df16cc1

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Sergiu Gatlan

...
...

CISA has ordered federal agencies to urgently patch a critical unauthenticated remote code execution vulnerability (CVE-2026-48907) in the Widget Factory Joomla Content Editor (JCE) plugin that allows attackers to upload and execute PHP by creating editor profiles; the flaw is being actively exploited with public exploit code and automated attacks, JCE released version 2.9.99.6 to fix it, and compromised sites require backup of rogue profiles, updating, credential changes, and full server-side malware scans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.