CISA flags maximum-severity Joomla JCE flaw exploited in the wild (CVE-2026-48907)
America's cyber agency CISA has added a maximum-severity Joomla flaw to its catalog of bugs under active attack. The weakness in the Widget Factory JCE editor lets an unauthenticated attacker upload and run code, taking full control of a vulnerable web server. Working exploit cod
On June 17 2026, CISA added CVE-2026-48907 to its Known Exploited Vulnerabilities catalog. The improper access control flaw in the Widget Factory Joomla Content Editor (JCE) carries a maximum CVSS score of 10.0. By sending crafted requests to an import function, an unauthenticated attacker can create a rogue editor profile, upload a malicious PHP file and execute it, deploying a web shell for full remote control of the server. Public exploit code and automated attacks are in the wild. The issue is fixed in JCE 2.9.99.5. CISA ordered federal agencies to patch by Friday, June 19.