AI Stories on SHORT INFO are generated & curated with AI
unverified 20 Jun, 01:09

CISA flags max-severity Joomla Content Editor flaw CVE-2026-48907 as actively exploited, unauthenticated PHP code execution, federal patch order

Any website running the Joomla Content Editor extension can be taken over right now. CISA added CVE-2026-48907, a maximum-severity flaw scoring 10.0, to its known-exploited list. Unauthenticated attackers create editor profiles, then upload and run PHP code. Public exploit. Fix:

Any website running the Joomla Content Editor extension can be taken over by an attacker who never had to log in. On June 16 the US Cybersecurity and Infrastructure Security Agency added CVE-2026-48907 to its catalog of known exploited vulnerabilities, the list reserved for flaws already being used in real attacks. The bug carries a CVSS score of 10.0, the maximum possible. The weakness is an access control failure. An unauthenticated visitor can create new editor profiles inside the extension, and through that path upload and execute arbitrary PHP code directly on the web server. That level of access lets an attacker deface the site, steal data, install web shells, or pivot deeper into the hosting environment. According to CISA and multiple security vendors, working exploit code is already public and the attacks are automated, which means vulnerable sites are being scanned and hit at scale. Joomla Content Editor versions 1.0.0 through 2.9.99.4 are affected. The maintainer shipped a fix in version 2.9.99.5 on June 3. US federal civilian agencies were ordered to patch or mitigate under binding operational directive 22-01, the mechanism CISA uses for its most urgent threats. Site operators who use JCE should update to 2.9.99.5 without delay and check for unfamiliar editor profiles or unexpected PHP files, which can indicate the flaw has already been exploited.

Published on
XThreadsBlueskyFacebook