• News/
  • bleepingcomputer-20260617100924

CISA orders feds to patch max severity Joomla plugin flaw by Friday

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 17, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in the wild. Tracked as CVE-2026-48907, this vulnerability can be exploited by threat actors without privileges to achieve code execution via low-complexity attacks targeting Joomla deployments that use the JCE WYSIWYG editor plugin. "Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users," CISA warned on Tuesday. The JCE security team addressed this in early June with the release of JCE Pro 2.9.99.6, warning users to patch their installation as soon as possible. "If you have not yet updated, please do so immediately. The vulnerability is being actively exploited, working exploit code is public, and the attacks are automated, so a site with no public registration is not safe," it said. "One important point: updating closes the entry point but does not clean a site that was already compromised. If you were hit before updating, the update will not remove what the attacker left behind." To clean compromised sites, users are advised to first back up the rogue profiles for further investigation, then update to JCE 2.9.99.6 or later, delete the attacker's profile, change all passwords (including those for the administ...

Read full article

Affected Software

1 affected component
Widget Factory JCE Pro<2.9.99.6
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of the CISA advisory regarding Joomla plugins?

The main focus is on a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that requires urgent patching.

2

What is the CVE identifier associated with the Joomla plugin vulnerability?

The vulnerability is tracked as CVE-2026-48907.

3

Why is this Joomla plugin vulnerability considered critical?

It is considered critical because it is actively being exploited in the wild.

4

What is the deadline given by CISA for federal agencies to patch this flaw?

CISA has ordered federal agencies to patch the flaw by Friday.

5

Which specific product is affected by this high-severity vulnerability?

The affected product is the Widget Factory JCE Pro plugin.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203