HackMyIP
← Back to News
2026-06-17 The Hacker News

CISA Adds Critical Joomla JCE RCE Flaw to KEV Amid Active Exploitation

VulnerabilitySupply Chain

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity flaw in Widget Factory's Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog, confirming the bug is being actively weaponized in the wild. Tracked as CVE-2026-48907 with a CVSS score of 10.0, the improper access control vulnerability allows unauthenticated attackers to create new editor profiles, upload PHP files, and achieve arbitrary code execution on the underlying server. The flaw affects JCE versions 1.0.0 through 2.9.99.4 and was patched in version 2.9.99.5, released June 3, 2026. Federal Civilian Executive Branch (FCEB) agencies have been ordered to apply the fix by June 19, 2026, and administrators are urged to patch immediately, as working exploit code is public and attacks are fully automated. Critically, Joomla warned that even sites without public registration are exposed, and updating closes the entry point but will not remediate a site that was already compromised. Defenders should audit web server access logs for unauthenticated requests to index.php?option=com_jce&task=profiles.import and run a port scanner to identify any suspicious services that may indicate a planted web shell. Phil E. Taylor of mySites.guru confirmed attackers are using rogue editor profiles to drop web shells for persistent backdoor access.

Separately, e-commerce security firm Sansec disclosed a large-scale supply chain attack that compromised more than one million WordPress sites using the OptinMonster, TrustPulse, and PushEngage plugins. Attackers injected malicious JavaScript designed to wait for a logged-in administrator session, then silently create a backdoor admin account and install a self-hiding backdoor plugin to maintain persistence. Administrators of these plugins should review user accounts, audit installed plugins against known-good inventories, and verify their site's TLS posture using an SSL/TLS checker to ensure no unauthorized certificates were issued during the intrusion window.

In a third incident, researchers uncovered a WordPress site compromised with a rogue plugin named "Beloved PBN Entegrasyonu" that exfiltrated the site's URL to an external API on every page load and injected attacker-controlled HTML or JavaScript into page footers. The initial access vector remains unclear, but the attackers staged two PHP web shells on the server after gaining a foothold. Site owners are advised to conduct a full WHOIS lookup on any unfamiliar outbound domains, scan for unauthorized admin accounts, and verify that file integrity monitoring is in place to detect tampering with core CMS files and plugin directories.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →