Joomla site owners using the JCE editor plugin are being targeted in active attacks that can let outsiders take over websites. The flaw, CVE-2026-48907, affects JCE Pro versions before 2.9.99.5 and lets unauthenticated attackers upload editor profiles and then arbitrary files, leading to PHP code execution on the server. Joomla says public exploit code exists, attacks are automated, and version 2.9.99.6 adds further protections and indicators of compromise.
Why it matters: This is urgent for organizations and individuals running Joomla sites because attackers can break in without an account and leave backdoors behind. Update immediately, then check for compromise because patching closes the hole but does not remove anything attackers already installed.
info@thehackernews.com (The Hacker News)
2026.07.08
84% relevant
This article adds that CISA has placed the Joomla JCE flaw CVE-2026-48907 in KEV, which strengthens the exploitation signal and increases patching urgency for affected Joomla sites.
Sergiu Gatlan
2026.06.17
97% relevant
This is the same underlying event: active exploitation of CVE-2026-48907 in the JCE Joomla plugin. The new information is that CISA has added the flaw to the Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to patch or mitigate by Friday under BOD 26-04.
Ionut Arghire
2026.06.17
100% relevant
The article establishes a distinct exploited-vulnerability event for Joomla JCE, separate from the already tracked LiteSpeed KEV story, with its own CVE, affected versions, exploitation details, and update guidance.
← Back to all stories