CISA orders feds to patch max severity Joomla plugin flaw by Friday
ID: 74c9f73b-f400-517c-b38b-c4e06df16cc1
STIX ID: report--74c9f73b-f400-517c-b38b-c4e06df16cc1
Feed Name: Bleeping Computer
CISA has ordered federal agencies to urgently patch a critical unauthenticated remote code execution vulnerability (CVE-2026-48907) in the Widget Factory Joomla Content Editor (JCE) plugin that allows attackers to upload and execute PHP by creating editor profiles; the flaw is being actively exploited with public exploit code and automated attacks, JCE released version 2.9.99.6 to fix it, and compromised sites require backup of rogue profiles, updating, credential changes, and full server-side malware scans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
