CISA Flags Joomla JCE Flaw, Cisco SD-WAN Zero-Days Mount
CISA flags a critical Joomla plugin flaw as actively exploited while Cisco discloses two more SD-WAN zero-days under attack

CISA added a critical Joomla JCE plugin flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by Friday. The vulnerability, CVE-2026-48907, allows unauthenticated attackers to create editor profiles and upload PHP code, leading to full remote code execution. As BleepingComputer reported, the flaw carries a CVSS 10.0 severity and is already under active exploitation in the wild. The Hacker News noted that the JCE extension is widely deployed across Joomla-based sites, making this a high-priority patch for any organization running the CMS. SecurityWeek confirmed that attackers are actively chaining the exploit in real-world campaigns.
Cisco disclosed two additional critical SD-WAN vulnerabilities that are being actively exploited, continuing a relentless wave of zero-day attacks against its Catalyst SD-WAN product family. CVE-2026-20127 is a CVSS 10.0 peering authentication flaw affecting the SD-WAN Controller, Manager, and Validator that allows unauthenticated remote attackers to gain full administrative access. CVE-2026-20182, also CVSS 10.0, is a control connection handling vulnerability that The Register reported was discovered after being disclosed in February 2026. BleepingComputer detailed that CVE-2026-20182 has been added to CISA's KEV catalog, and Help Net Security noted this marks the seventh SD-WAN zero-day exploited in 2026 alone. Organizations running Cisco SD-WAN should prioritize patching immediately as threat actors continue to target these systems for network access and lateral movement.
A wave of legacy vulnerabilities with high EPSS scores continues to pose significant risk to unpatched systems, underscoring the enduring danger of unmanaged software inventory. CVE-2003-0545 is a double-free vulnerability in OpenSSL 0.9.7 that allows remote code execution via malformed ASN.1-encoded client certificates, with an EPSS score of 0.85. CVE-2003-0466 is an off-by-one error in the fb_realpath() function used in wu-ftpd 2.5.0 through 2.6.2 that enables arbitrary code execution, carrying an EPSS of 0.78. CVE-2004-0847 is a Microsoft .NET forms authentication bypass for ASP.NET that allows attackers to access restricted .aspx files using backslash or encoded backslash characters, with an EPSS of 0.76. CVE-2002-0391 is an integer overflow in the xdr_array function in SunRPC-based systems including glibc and dietlibc that permits remote code execution by passing a large number of arguments, with an EPSS of 0.58. While these are decades-old flaws, their high EPSS scores indicate active scanning or exploitation attempts, and any remaining unpatched instances represent critical risk.
Several additional high-severity legacy vulnerabilities with EPSS scores above 0.10 remain actively targeted by automated scanning and exploitation frameworks. CVE-2002-1484 affects DB4Web servers configured with verbose debug messages, allowing remote attackers to use the server as a proxy for TCP port scanning, with an EPSS of 0.14. CVE-2002-0083 is an off-by-one error in OpenSSH 2.0 through 3.0.2's channel code that allows privilege escalation, with an EPSS of 0.15. CVE-1999-0006 is a buffer overflow in Qualcomm qpopper POP servers that grants remote root access via a long PASS command, with an EPSS of 0.12. CVE-1999-0066 is a remote code execution vulnerability in the AnyForm CGI script, with an EPSS of 0.12. CVE-2000-0944 allows remote attackers to change the admin password in CGI Script Center News Update 1.1 without knowing the original password, with an EPSS of 0.11. CVE-1999-0426 involves default /dev/kmem permissions in Linux kernels before 2.0.36 enabling IP spoofing, with an EPSS of 0.11. These vulnerabilities are unlikely to exist in modern environments but remain dangerous for legacy or air-gapped systems that have not been updated.
A collection of PHP remote file inclusion and open proxy vulnerabilities from the early 2000s continues to appear in scanning data, primarily targeting outdated content management systems and web applications. CVE-2004-0285 affects AllMyVisitors, AllMyLinks, and AllMyGuests through the include/footer.inc.php script, allowing arbitrary PHP code execution via the _AMVconfig[cfg_serverpath] parameter, with an EPSS of 0.08. CVE-2004-2061 in RiSearch 1.0.01 and RiSearch Pro 3.2.06 enables attackers to use the show.pl script as an open proxy or read arbitrary local files, with an EPSS of 0.06. CVE-2004-0030 in PHPGEDVIEW 2.61 allows remote file inclusion via the PGV_BASE_DIRECTORY parameter, with an EPSS of 0.07. CVE-2002-1816 is an off-by-one buffer overflow in ATPhttpd 0.4b and earlier via a long HTTP GET request, with an EPSS of 0.09. CVE-2001-0766 affects Apache on MacOS X Client 10.0.3 with HFS+ file systems, allowing attackers to bypass access restrictions through case-mismatched URLs, with an EPSS of 0.09. CVE-2001-0609 is a format string vulnerability in Infodrom cfingerd 1.4.3 and earlier via malformed ident replies passed to syslog, with an EPSS of 0.18. These vulnerabilities primarily threaten organizations still running unsupported web applications or those with weak asset management.
The Cisco SD-WAN exploitation campaign continues to generate significant industry analysis and response. CyberScoop reported that a persistent threat group is behind the ongoing attacks, while The Record noted that CISA ordered all federal agencies to patch CVE-2026-20182 by a specific deadline. Tenable published a FAQ addressing the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities, and Rapid7 included a module for CVE-2026-20182 in its Metasploit framework, lowering the barrier to exploitation. Check Point Research highlighted the SD-WAN vulnerabilities in its threat intelligence report, and Risky Business covered the ongoing campaign in its weekly podcast. The breadth of coverage underscores the severity and persistence of this threat, which has now resulted in seven distinct zero-day vulnerabilities exploited against Cisco SD-WAN products in 2026 alone.