Widget Factory Joomla Content Editor JCE actively exploited improper access control security flaw (CVE-2026-48907)
Vulnerability
Summary
Hide ▲
Show ▼
The Widget Factory Joomla Content Editor (JCE) flaw CVE-2026-48907 has been added to CISA's KEV catalog after evidence of active exploitation, putting affected Joomla sites at risk of PHP code upload and execution. The issue is an improper access control weakness that lets unauthenticated users create editor profiles and reach arbitrary code execution. JCE 1.0.0 through 2.9.99.4 are affected, and version 2.9.99.5 contains the fix.
Related Happenings
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation Wave
H score42
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation WaveAbout this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)
Vulnerability
H score59
First: 13.07.2026 08:36
Last: 13.07.2026 08:36
Sources 1
About this happening:
CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...
Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)
VulnerabilityAbout this happening: CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...
CISA KEV remediation order for CVE-2026-48907
Public Sector Action
H score89
First: 17.06.2026 08:50
Last: 17.06.2026 08:50
Sources 1
How related:
On Tuesday, CISA added the vulnerability to its list of actively exploited vulnerabilities and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as required by Binding Operational Directive (BOD) 26-04.
About this happening:
CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
CISA KEV remediation order for CVE-2026-48907
Public Sector ActionHow related: On Tuesday, CISA added the vulnerability to its list of actively exploited vulnerabilities and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as required by Binding Operational Directive (BOD) 26-04.
About this happening: CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
17.06.2026 08:50 1 articles · 28d ago
Widget Factory ships JCE 2.9.99.5 to close editor-profile access flaw
Mitigation Patch UpdateWidget Factory released JCE version 2.9.99.5 on June 3, 2026 to fix an improper access control flaw in Widget Factory Joomla Content Editor that let unauthenticated users create editor profiles and upload or execute PHP code; JCE versions 1.0.0 through 2.9.99.4 were affected.
Show sources
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — thehackernews.com — 17.06.2026 08:50
-
17.06.2026 08:50 3 articles · 28d ago
CISA adds CVE-2026-48907 in Widget Factory Joomla Content Editor to KEV catalog
Initial DisclosureCISA added CVE-2026-48907 in Widget Factory Joomla Content Editor to the Known Exploited Vulnerabilities catalog on June 17, 2026 after evidence of active exploitation; the maximum-severity improper access control flaw could enable arbitrary code execution through unauthenticated editor-profile creation.
Show sources
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — thehackernews.com — 17.06.2026 08:50
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — thehackernews.com — 17.06.2026 08:50
- CISA orders feds to patch max severity Joomla plugin flaw by Friday — www.bleepingcomputer.com — 17.06.2026 13:09