Vulnerability intelligence
CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVSS Score
10
Critical
EPSS — Exploit Probability
56%
Riskier than 99% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-16
Remediation
Patch available
Federal deadline 2026-06-19
6 articles across 5 outlets · first covered Jun 16, 2026 · latest Jun 17, 2026
Tracked incidents
Coverage timeline
-
CISA flags critical Joomla JCE bug enabling remote code executionsecurityaffairs.com · Jun 17, 2026
-
AdGuard blocks Joomla exploit and launches email tracking shieldsecurityonline.info · Jun 17, 2026
-
Joomla and LiteSpeed Bugs Let Attackers Run Code, Gain Rootwww.securityweek.com · Jun 17, 2026
-
WooCommerce stores hit by payment skimmer (CVE-2026-48907)securityonline.info · Jun 17, 2026
-
CISA Adds CVE-2026-48907 Joomla Editor Flaw to Known Exploited Listwww.cisa.gov · Jun 16, 2026
-
CISA adds critical Joomla editor flaw CVE-2026-48907 to KEVcisa.gov · Jun 16, 2026