Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV remediation order for CVE-2026-48907

Public Sector Action
First reported
Last updated
Happening score
H score 89
2 unique sources, 2 articles

Summary

Hide ▲

CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Joomla flaw. The directive centers on Widget Factory Joomla Content Editor (JCE) and a maximum-severity access-control issue that can enable PHP code upload and execution. The action increases urgency for federal operators because the vulnerability is already treated as a known exploited weakness with a short compliance window.

Related Happenings

CISA KEV directive for Joomla extension flaws

Public Sector Action
H score36 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...

Joomla iCagenda and Balbooa Forms active RCE exploitation wave

Exploitation Wave
H score42 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....

Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)

Vulnerability
H score59 First: 13.07.2026 08:36 Last: 13.07.2026 08:36 Sources 1

About this happening: CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...

JCE Pro 2.9.99.6 patch for CVE-2026-48907

Security Patch Release
H score46 First: 17.06.2026 13:09 Last: 17.06.2026 13:09 Sources 1

How related: "The JCE security team addressed this in early June with the release of JCE Pro 2.9.99.6, warning users to patch their installation as soon as possible."

About this happening: JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...

Widget Factory Joomla Content Editor JCE actively exploited improper access control security flaw (CVE-2026-48907)

Vulnerability
H score89 First: 17.06.2026 08:50 Last: 17.06.2026 08:50 Sources 1

How related: Tracked as CVE-2026-48907, this vulnerability can be exploited by threat actors without privileges to achieve code execution via low-complexity attacks targeting Joomla deployments that use the JCE WYSIWYG editor plugin.

About this happening: The Widget Factory Joomla Content Editor (JCE) flaw CVE-2026-48907 has been added to CISA's KEV catalog after evidence of active exploitation, putting affected Joo...

Timeline

  1. 17.06.2026 08:50 1 articles · 28d ago

    Widget Factory releases JCE 2.9.99.5 to fix unauthenticated editor-profile uploads

    Mitigation Patch Update

    Widget Factory released JCE version 2.9.99.5 on June 3, 2026 to fix insufficient access controls that let unauthenticated users upload editor profiles and could enable PHP code upload and execution in Widget Factory Joomla Content Editor (JCE).

    Show sources
  2. 17.06.2026 08:50 3 articles · 28d ago

    CISA adds CVE-2026-48907 to KEV and orders FCEB remediation by June 19, 2026

    Legal Policy Action Update

    CISA added CVE-2026-48907 affecting Widget Factory Joomla Content Editor (JCE) to the Known Exploited Vulnerabilities (KEV) catalog after citing active exploitation, and Federal Civilian Executive Branch (FCEB) agencies were ordered to apply the fixes by June 19, 2026. The action addresses a maximum-severity improper access control flaw that can enable PHP code upload and execution through unauthenticated editor-profile creation.

    Show sources