CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

June 25, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting the Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. The flaw, tracked as CVE-2026-48907 with a CVSS score of 10.0, is an improper access control issue that allows unauthenticated users to upload and execute PHP code via the creation of new editor profiles. It impacts JCE versions 1.0.0 through 2.9.99.4 and has been patched in version 2.9.99.5, released on June 3, 2026.

Joomla has confirmed that the vulnerability is being actively exploited with public exploit code and automated attacks. The CMS provider warns that updating closes the entry point but does not clean already compromised sites. Users are advised to check for suspicious editor profiles and audit web server access logs for unauthenticated requests to the profile import task. Phil E. Taylor of mySites.guru revealed that attackers are using the flaw to import rogue editor profiles and drop web shells for persistent backdoor access. Federal Civilian Executive Branch (FCEB) agencies must apply fixes by June 19, 2026.

Additionally, the article details multiple campaigns targeting WordPress sites. Sansec reported a supply chain attack campaign affecting over 1 million sites via OptinMonster, TrustPulse, and PushEngage plugins, where threat actors injected malicious JavaScript to create backdoor admin accounts and install self-hiding backdoor plugins. Another campaign involved unknown attackers compromising a WordPress site to embed a fake plugin named “Beloved PBN Entegrasyonu” that injected hidden backlinks for a Private Blog Network (PBN), likely tied to gambling and adult affiliate niches. Sucuri researcher Puja Srivastava noted that the campaign is operated by a Turkish-speaking threat actor and damages search rankings.

CVEs: CVE-2026-48907, CVE-2026-11645

Attack groups: Turkish-speaking threat actor

Companies: Widget Factory, Joomla, OptinMonster, TrustPulse, PushEngage, Sansec, Sucuri, mySites.guru

Products: Joomla Content Editor (JCE), OptinMonster, TrustPulse, PushEngage, Beloved PBN Entegrasyonu