CVE-2026-48907
Known exploited · CISA KEV
EPSS 78% (100th percentile).
CISA federal remediation date Jun 19 · date passed
Vulnerabilities · 4 days ago
CSIRT-ITA says it has seen a significant rise in active exploitation of CVE-2026-48907 against exposed Joomla Content Editor (JCE) installations, with most attacks used to drop webshells for site defacement. The flaw was already patched by the vendor, but the public servers being hit are the ones that stayed exposed.
The attack abuses JCE’s profile import path: a fake import is sent to the plugin, and weak access checks let PHP land in a web-served directory. Once that file is in place, the attacker has a backdoor that keeps running after the first request, and CSIRT-ITA says some intrusions also plant a malicious-looking Joomla extension to preserve uploader access.
For internet-facing Joomla sites, the exposure is no longer just a bad request on a plugin endpoint. If the site was left unpatched and was already hit, the lingering problem is server compromise and a planted foothold, not only the vulnerable version itself.
Known exploited · CISA KEV
EPSS 78% (100th percentile).
CISA federal remediation date Jun 19 · date passed
1 source covering this story
Questo CSIRT ha recentemente registrato, nel contesto nazionale, un aumento significativo di sfruttamenti attivi della CVE-2026-48907 – già sanata dal vendor e trattata nell’ambito dell’AL02/260615/CSIRT-ITA – ai danni di server web esposti.
Part of the PlainSec briefing for 2026-09-18