securityaffairs.com 6/17/2026, 3:40:23 PM · external

CISA flags critical Joomla JCE bug enabling remote code execution

CISA flags critical Joomla JCE bug enabling remote code execution
Developing story vulnerability 12 articles tracked
CISA adds Joomla Content Editor flaw (CVE-2026-48907) to KEV catalogue
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in the Widget Factory Joomla Content Editor (JCE), identified as CVE-2026-48907 with a CVSS score of 10.0, to its Known Exploited Vulnerabilities catalog. This vulnerability allows unauthenticated users to create new editor profiles, leading to PHP code uploads and execution. It affects JCE versions 1.0.0 through 2.9.99.4 and was patched in version 2.9.99.5 released on June 3, 2026.

Federal agencies must address this vulnerability by June 19, 2026, to protect their networks, and private organizations are also advised to review and mitigate this threat.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline