CVE-2026-48907
Known exploited · CISA KEV
EPSS 78% (100th percentile).
CISA federal remediation date Jun 19 · date passed
Vulnerabilities & Exploits · Web App Attack
CSIRT-ITA says it has seen a significant rise in active exploitation of CVE-2026-48907 against exposed Joomla Content Editor (JCE) installations, with most attacks used to drop webshells for site defacement. The flaw was already patched by the vendor, but the public servers being hit are the ones that stayed exposed.
The attack abuses JCE’s profile import path: a fake import is sent to the plugin, and weak access checks let PHP land in a web-served directory. Once that file is in place, the attacker has a backdoor that keeps running after the first request, and CSIRT-ITA says some intrusions also plant a malicious-looking Joomla extension to preserve uploader access.
For internet-facing Joomla sites, the exposure is no longer just a bad request on a plugin endpoint. If the site was left unpatched and was already hit, the lingering problem is server compromise and a planted foothold, not only the vulnerable version itself.
1 source · Sep 17
Known exploited · CISA KEV
EPSS 78% (100th percentile).
CISA federal remediation date Jun 19 · date passed
CSIRT Italia / ACN
Joomla JCE: rilevato sfruttamento CVE-2026-48907 al fine di distribuire webshell utilizzate per defacement
Questo CSIRT ha recentemente registrato, nel contesto nazionale, un aumento significativo di sfruttamenti attivi della CVE-2026-48907 – già sanata dal vendor e trattata nell’ambito dell’AL02/260615/CSIRT-ITA – ai danni di server web esposti.
originalPart of the PlainSec briefing for 2026-09-17
Every edition of this story: JCE Flaw Is Turning Joomla Sites Into Webshell Hosts