Critical severityCISA KEVNVD Advisory· Published Jun 5, 2026· Updated Jun 16, 2026
CVE-2026-48907
CVE-2026-48907
Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
10- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe Hacker News · Jul 13, 2026
- Australia warns of global campaign targeting vulnerable CMS platformsBleepingComputer · Jul 11, 2026
- Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesThe Hacker News · Jul 10, 2026
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- Breach Roundup: ShinyHunters Leaks 26M MSG RecordsGovInfoSecurity · Jun 19, 2026
- CISA orders feds to patch max severity Joomla plugin flaw by FridayBleepingComputer · Jun 17, 2026
- Joomla, LiteSpeed Vulnerabilities Exploited in AttacksSecurityWeek · Jun 17, 2026
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionThe Hacker News · Jun 17, 2026
- WordPress CVE-2026-48907 Added to CISA KEV Under Active ExploitationVypr Intelligence · Jun 16, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts