Find notable cyber news and cases, enriched with sources, timelines, and signals.

Widget Factory Joomla Content Editor JCE actively exploited improper access control security flaw (CVE-2026-48907)

Vulnerability
First reported
Last updated
Happening score
H score 89
2 unique sources, 2 articles

Summary

Hide ▲

The Widget Factory Joomla Content Editor (JCE) flaw CVE-2026-48907 has been added to CISA's KEV catalog after evidence of active exploitation, putting affected Joomla sites at risk of PHP code upload and execution. The issue is an improper access control weakness that lets unauthenticated users create editor profiles and reach arbitrary code execution. JCE 1.0.0 through 2.9.99.4 are affected, and version 2.9.99.5 contains the fix.

Related Happenings

CISA KEV directive for Joomla extension flaws

Public Sector Action
H score36 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...

Joomla iCagenda and Balbooa Forms active RCE exploitation wave

Exploitation Wave
H score42 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....

Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)

Vulnerability
H score59 First: 13.07.2026 08:36 Last: 13.07.2026 08:36 Sources 1

About this happening: CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...

CISA KEV remediation order for CVE-2026-48907

Public Sector Action
H score89 First: 17.06.2026 08:50 Last: 17.06.2026 08:50 Sources 1

How related: On Tuesday, CISA added the vulnerability to its list of actively exploited vulnerabilities and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as required by Binding Operational Directive (BOD) 26-04.

About this happening: CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
H score53 First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...

Timeline

  1. 17.06.2026 08:50 1 articles · 28d ago

    Widget Factory ships JCE 2.9.99.5 to close editor-profile access flaw

    Mitigation Patch Update

    Widget Factory released JCE version 2.9.99.5 on June 3, 2026 to fix an improper access control flaw in Widget Factory Joomla Content Editor that let unauthenticated users create editor profiles and upload or execute PHP code; JCE versions 1.0.0 through 2.9.99.4 were affected.

    Show sources
  2. 17.06.2026 08:50 3 articles · 28d ago

    CISA adds CVE-2026-48907 in Widget Factory Joomla Content Editor to KEV catalog

    Initial Disclosure

    CISA added CVE-2026-48907 in Widget Factory Joomla Content Editor to the Known Exploited Vulnerabilities catalog on June 17, 2026 after evidence of active exploitation; the maximum-severity improper access control flaw could enable arbitrary code execution through unauthenticated editor-profile creation.

    Show sources