Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-cataloginternet-facing-service-vulnerabilityproof-of-concept-release

CISA Flags Actively Exploited JCE Joomla Plugin RCE

Updated 4d agoFirst seen Jun 17, 202614 sources

CISA added CVE-2026-48907 to its Known Exploited Vulnerabilities catalog after reports of active exploitation against the Widget Factory Joomla Content Editor (JCE) plugin. The maximum-severity improper access control flaw lets unauthenticated attackers create new editor profiles and then upload and execute PHP code, resulting in remote code execution on vulnerable Joomla sites. The KEV update raised the catalog total to 1,622 entries and set a federal remediation deadline of 2026-06-19 under BOD 26-04.

Vendor and media reporting said the issue affects JCE versions 1.0.0 through 2.9.99.4, with fixes released in 2.9.99.5 and later, including JCE Pro 2.9.99.6. The JCE team also issued a free patch for older sites and warned that public exploit code is available, attacks are automated, and sites without public registration can still be targeted. Security reporting noted that applying the update blocks the initial access path but does not remove any persistence, web shells, or malware that attackers may already have deployed on compromised servers.

Share:
CISA Flags Actively Exploited JCE Joomla Plugin RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jun 19, 20264d ago

CISA orders federal agencies to remediate JCE flaw by June 19

Following KEV inclusion, CISA directed Federal Civilian Executive Branch agencies to remediate CVE-2026-48907 by June 19, 2026 under Binding Operational Directive guidance. Reporting also noted public exploit code exists and attacks are automated.

CISA orders feds to patch max severity Joomla plugin flaw by Friday
Jun 17, 20266d ago

JCE recommends upgrading to version 2.9.99.6

A new reference states that administrators should upgrade Joomla Content Editor to JCE 2.9.99.6 immediately, or at minimum to 2.9.99.5, indicating a newer recommended release beyond the previously documented fix. The same guidance also suggests temporarily blocking PHP execution in the tmp/ directory while investigating compromise.

Pre-Auth RCE in Joomla Content Editor: Profile Import to PHP Execution (CVE-2026-48907)
Jun 16, 20267d ago

CISA adds CVE-2026-48907 to the KEV catalog

CISA added CVE-2026-48907, a Widget Factory Joomla Content Editor improper access control flaw enabling unauthenticated profile creation and PHP upload/execution, to its Known Exploited Vulnerabilities catalog. The KEV entry set a remediation due date of June 19, 2026 and indicates exploitation in the wild.

Add Updated KEV Files for 2026-06-16 · cisagov/kev-data@c5df291 · GitHub
Jun 12, 202611d ago

JCE publishes security update and free patch for older sites

The JCE project published a security update announcement and offered a free patch for older sites. This reflects the vendor's public response to the vulnerability.

JCE security update, and a free patch for older sites
Jun 9, 202614d ago

Public GitHub PoC exploit for CVE-2026-48907 is published

A public proof-of-concept exploit for the JCE flaw CVE-2026-48907 was published on GitHub. Reporting tied the PoC to subsequent automated attacks exploiting the vulnerability in the wild.

Max severity Joomla Content Editor extension flaw targeted in automated attacks | news | SC Media
Jun 6, 202617d ago

JCE releases version 2.9.99.6 with additional hardening

JCE followed its June 3 fix for CVE-2026-48907 by releasing version 2.9.99.6 on June 6, 2026 with additional hardening measures. The report says administrators should investigate for compromise because patching alone does not remove implanted malware.

CVE-2026-48907, LiteSpeed CPanel Plugin Flaws Exploited
Jun 3, 202620d ago

JCE releases fix for CVE-2026-48907 in version 2.9.99.5

Widget Factory fixed CVE-2026-48907, an improper access control flaw in Joomla Content Editor, in JCE version 2.9.99.5. Security Affairs states this release occurred on June 3, 2026 and that affected versions were 1.0.0 through 2.9.99.4.

U.S. CISA adds Widget Factory Joomla Content Editor (JCE) flaw to its Known Exploited Vulnerabilities catalog
Dec 25, 20256mo ago

JCE 2.9.99.6 identified as fix for CVE-2026-48907

A new reference states that CVE-2026-48907 affects JCE 2.9.99.5 and was fixed in version 2.9.99.6 and later. The report also shares indicators of compromise, including suspicious requests to the JCE profile import endpoint and unexpected PHP or related files in Joomla environments.

����������� ����������� ���������� � JCE, ���������� ��� CMS Joomla
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

27 LINKEDOpen in app
Affected products
9 linked
JoomlaCpanelWordpressApache Http ServerCatalyst SD-WAN ManagerPeoplesoft Enterprise PeopletoolsNginxCpanel PluginJoomla-Cms
Organizations
14 linked
Litespeed TechnologiesThe Cyber ExpressWidget FactoryGitHubYesWeHackLiteSpeedWatchfulCisco SystemsBeazley SecurityOracleSecurity AffairsW3TechsmySites.guruJoomla Content Editor
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.