JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch Release
Summary
Hide ▲
Show ▼
JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addresses an improper access control flaw that could let unauthenticated attackers upload and execute PHP code on Joomla deployments. Public reporting says the flaw is actively exploited and users should patch installations as soon as possible.
Related Happenings
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation Wave
H score42
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation WaveAbout this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
F5 security patch release for CVE-2026-42530
Security Patch Release
H score39
First: 18.06.2026 20:32
Last: 18.06.2026 20:32
Sources 1
About this happening:
F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
F5 security patch release for CVE-2026-42530
Security Patch ReleaseAbout this happening: F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
CISA KEV remediation order for CVE-2026-48907
Public Sector Action
H score89
First: 17.06.2026 08:50
Last: 17.06.2026 08:50
Sources 1
How related:
On Tuesday, CISA added the vulnerability to its list of actively exploited vulnerabilities and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as required by Binding Operational Directive (BOD) 26-04.
About this happening:
CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
CISA KEV remediation order for CVE-2026-48907
Public Sector ActionHow related: On Tuesday, CISA added the vulnerability to its list of actively exploited vulnerabilities and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as required by Binding Operational Directive (BOD) 26-04.
About this happening: CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
H score42
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
Timeline
-
17.06.2026 13:09 2 articles · 28d ago
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Initial DisclosureJCE Pro 2.9.99.6 was released in early June 2026 to remediate CVE-2026-48907 in the Joomla editor plugin. The patch closes the vulnerable access-control path, but sites already compromised still need separate cleanup.
Show sources
- CISA orders feds to patch max severity Joomla plugin flaw by Friday — www.bleepingcomputer.com — 17.06.2026 13:09
- CISA orders feds to patch max severity Joomla plugin flaw by Friday — www.bleepingcomputer.com — 17.06.2026 13:09