The Australian Cyber Security Centre (ACSC) has issued a warning about a massive CMS exploit campaign targeting websites worldwide. The CMS exploit campaign, as described, relies on active scanning for known vulnerabilities and rapid installation of webshells (also in Australia), with a particular focus on small and medium-sized businesses. According to the announcement, the attackers are “scanning” the internet for vulnerable installations and exploiting known weaknesses in platforms and plugins to install webshells and gain remote control.

The ACSC emphasizes that the CMS exploit campaign scenarios are mainly related to vulnerabilities that allow unauthenticated file upload, remote code execution (RCE), SSRF or even deserialisation issues, as a result of which the attacker can “plant” a webshell and use it as a permanent backdoor. More technical details and the list of software can be found in the relevant ACSC.
See also: ACSC warns of SonicWall access vulnerability
What a webshell can do to a compromised website
A webshell is usually a small script (e.g. PHP) that is uploaded to the server and allows the attacker to execute commands, upload/download files, and navigate the system as if they were a legitimate administrator. The ACSC warns that the effects are not limited to simply “altering” the site: there can be theft of credentials from forms, extraction of data located in the webroot, as well as installation of additional malware for further attacks.
Even when the initial intrusion is on a “simple” website, a webshell can be a springboard for a broader network breach, especially if the server communicates with internal systems, databases, or back-office services. That’s why ACSC recommends that webshell incidents be treated as a full compromise rather than as an isolated file corruption.

CMS Exploit Campaign: Platforms and CVEs on Alert
In the announcement, the ACSC lists indicative software, plugins and CVEs that are allegedly being exploited in real attacks as part of the CMS exploitation campaign. The list is extensive and includes multiple ecosystems, with an emphasis on WordPress plugins, but also references to other CMSs such as Craft, MaxSite, MetInfo and Joomla.
Among others, vulnerabilities are reported in: Simple File List (CVE-2025-34085 / CVE-2020-36847), WavePlayer (CVE-2025-12057), BerqWP (CVE-2025-7443), WPBookit (CVE-2025-7852), Ninja Forms (CVE-2026-0740), ThemeREX Addons (CVE-2026-1969), Breeze Cache (CVE-2026-3844), pay-uz (CVE-2026-31843), ACF Extended (CVE-2025-13486), Sneeit Framework (CVE-2025-6389), WPvivid Backup (CVE-2026-1357), Gravity Forms (CVE-2025-12352), GutenKit/Hunk Companion (possible CVE-2024-9234), as well as and Craft CMS (CVE-2025-32432), MaxSite CMS (CVE-2026-3395), MetInfo CMS (CVE-2026-29014) and Joomla JCE (CVE-2026-48907), as reported by ACSC.
What administrators should do: checks, quarantine, updates
The ACSC recommends a series of immediate steps for those who fear they may have been affected by the CMS exploit campaign, starting with inspecting the CMS for webshells and checking the web directory for "anomalous" changes to public-facing files. If a vulnerable plugin is found, it is recommended to additionally check for suspicious file creation within the plugin folders, as well as review access logs for suspicious GET/POST to webshell paths.
Once a webshell is detected, the server should be considered compromised: isolate, audit authentication logs and network logs for suspicious connections, review historical logs for the initial exploit, and look for signs of persistence, lateral movement, and additional malware. In terms of remediation, the instructions are clear: patch vulnerable systems to prevent re-infection, quarantine/remove malicious files, and, if necessary, restore from a recent known “clean” backup.
See also: iCagenda: Critical RCE vulnerability exploited in Joomla site
On a more "preventive" level, ACSC urges organizations to keep core and plugins fully updated, consider automated patching where possible, temporarily disable plugins with active exploitation, and implement controls such as read-only web directories where applicable, monitoring/blocking unexpected file creation, path access restrictions, and monitoring for new processes "spawned" by the webserver (typical webshell behavior).
For businesses that rely on third-party hosting or management, the “prescription” is to share the warning with the provider and ask for confirmation that patches have been applied, that file integrity checks are in place, and that logs are being systematically monitored. The SecNews technical team notes that such campaigns usually “profit” from update delays: the sooner a patch is released, the smaller the exposure window.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
