HomeSecurityCISA adds Joomla JCE vulnerability to KEV List

CISA adds Joomla JCE vulnerability to KEV List

CISA has issued an urgent advisory for vulnerability CVE -2026-48907 , a critical vulnerability in the popular Widget Factory Joomla Content Editor (JCE), which allows unauthorized users to execute arbitrary PHP code on vulnerable servers. The US cybersecurity agency added the vulnerability to its Known Exploited Vulnerabilities (KEV) list , confirming that it is actively being exploited online. The bug has been rated CVSS 10.0 — the maximum severity rating.

Joomla JCE CISA

CVE-2026-48907 concerns an improper access control issue in the profiles.import handler of the JCE editor extension for Joomla . Specifically, inadequate access controls allowed unauthorized users to create new editor profiles , thus paving the way for PHP files to be uploaded and executed on the server . The exploit chain involves a lack of authorization, inadequate file validation, and the ability to bypass security checks for file uploads. The result is pre-authentication Remote Code Execution (RCE) — that is, full code execution without any login or user interaction required.

See also: CVE-2026-20262: Cisco SD-WAN Manager actively exploited

The vulnerable JCE range from 1.0.0 to 2.9.99.4. Widget Factory, the company that develops the extension, released version 2.9.99.5 on June 3, 2026, which addresses the issue. Version 2.9.99.6 with additional security enhancements. According to the release notes, "inadequate access controls allowed unauthorized users to upload editor profiles."

CISA adds Joomla JCE vulnerability to KEV List

The vulnerability is part of a broader pattern of CMS extensions, where attackers target third-party plugins and extensions instead of the core platform, as these often have weaker access controls and broader file upload capabilities. The attack chain is structurally similar to many recent website compromise campaigns that use upload flaws to gain server-side code execution.

See also: PeopleSoft: CISA adds CVE-2026-35273 to the KEV List

It is no coincidence that CISA was quick to add the bug to the KEV list — the existence of a functional exploit makes any vulnerable site an immediate target. Organizations using Joomla with the JCE extension installed should immediately upgrade to version 2.9.99.5 or later — preferably 2.9.99.6 for additional security hardening. If JCE is not required, it is recommended to completely uninstall it. In case the upgrade is delayed, administrators should restrict access via Web Application Firewall (WAF) and block suspicious requests to the profile import handler. Federal Civilian Executive Branch (FCEB) agencies have been instructed to implement the fixes by June 19, 2026 .

What Joomla administrators should do about CVE-2026-48907

Organizations using Joomla with the JCE extension should immediately upgrade to version 2.9.99.5 or later. If JCE is not required, it is recommended to completely uninstall it. In case the upgrade is delayed, administrators should restrict access via Web Application Firewall (WAF) and block suspicious requests to the profile import handler.

See also: CISA warns of critical vulnerability in PTC Windchill

CISA adds Joomla JCE vulnerability to KEV List

It is also important to check whether the site has already been compromised during the time the vulnerability was exposed. Administrators should look for suspicious profile handlers, webshells, unexpected PHP files in upload folders, and GIF/PHP polyglots. Monitoring logs for requests to the profile import handler from unauthorized sources is critical. After remediation, it is recommended to change all credentials and secrets associated with the Joomla, especially if there is evidence of file compromise or unauthorized profile creation. According to The Hacker News, the active exploitation of CVE-2026-48907 makes immediate action imperative for any organization managing a Joomla with the JCE extension.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS