www.cisa.gov 6/16/2026, 9:37:34 PM · external

CISA Adds CVE-2026-48907 Joomla Editor Flaw to Known Exploited List

Developing story vulnerability 2 articles tracked
CISA adds Widget Factory Joomla Content Editor flaw (CVE-2026-48907) to KEV
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog maintained by CISA serves as a vital resource for the cybersecurity community, helping organizations prioritize vulnerabilities that are actively exploited. The catalog includes a detailed entry for CVE-2026-48907, a vulnerability in the Widget Factory Joomla Content Editor that allows unauthorized PHP code execution through improper access control. Users are urged to apply mitigations per vendor instructions and adhere to CISA's guidance on security updates.

The KEV catalog is accessible in various formats, such as CSV and JSON, and organizations can nominate additional vulnerabilities for inclusion. Regular updates can be subscribed to for ongoing awareness.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline