Vulnerabilities & Exploits · Web App Attack

JCE Flaw Is Turning Joomla Sites Into Webshell Hosts

CSIRT-ITA says it has seen a significant rise in active exploitation of CVE-2026-48907 against exposed Joomla Content Editor (JCE) installations, with most attacks used to drop webshells for site defacement. The flaw was already patched by the vendor, but the public servers being hit are the ones that stayed exposed.

The attack abuses JCE’s profile import path: a fake import is sent to the plugin, and weak access checks let PHP land in a web-served directory. Once that file is in place, the attacker has a backdoor that keeps running after the first request, and CSIRT-ITA says some intrusions also plant a malicious-looking Joomla extension to preserve uploader access.

For internet-facing Joomla sites, the exposure is no longer just a bad request on a plugin endpoint. If the site was left unpatched and was already hit, the lingering problem is server compromise and a planted foothold, not only the vulnerable version itself.

1 source · Sep 17

CVE-2026-48907

NVD KEV

Known exploited · CISA KEV

EPSS 78% (100th percentile).

CISA federal remediation date Jun 19 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-09-17

Every edition of this story: JCE Flaw Is Turning Joomla Sites Into Webshell Hosts

More from today