The images in this article were generated with artificial intelligence. How we publish
The US Agency for Infrastructure and Cybersecurity. USA (CISA) has included in its catalogue of actively exploited vulnerabilities the critical failure identified as CVE-2026-48907, related to the JCE plugin (Widget Factory Joomla Content Editor) for Joomla, and has ordered federal agencies to apply emergency patches. Gravity is not only theoretical: the explosion works without credentials and the attack code is publicly available, making Joomla sites without public record into quick targets for automated attacks.
In simple terms, vulnerability allows attackers to create unauthorized editor profiles that facilitate the upload and run PHP files, so you can achieve remote code execution. Although the developer launched JCE Pro 2.9.99.6 to close the vector, update only blocks new intrusions; it does not remove artifacts that an attacker may have previously left on the server.

If you manage Joomla sites, the first step is to review and apply the official patch without delay: download the corrected version from the JCE project website and confirm the installed version in each affected instance. The page with the update is available at JCE Pro - downloads and the technical vulnerability register can be found in the NVD: CVE-2026-48907 (NVD).
Not to update is not the only acceptable option: if you cannot apply the patch immediately, it evaluates cutting off the public exposure of the plugin (blocking public editor routes with server rules or WAF, restricting access by IP, or temporarily disabling the plugin). For organizations dependent on cloud services, follow the CISA guidelines or withdraw the service if the mitigation is not feasible; the directive that requires prioritizing these actions is published by CISA in BOD 26-04.
If you suspect that a site was compromised before the patch, it comes as in an incident response: preserves evidence(exports suspicious profiles), immediately updates to the secure version, eliminates identified malicious profiles and files, and changes all credentials (management accounts, database and hosting credentials). He then performs a server-level forensic scan to search for web shells, back doors, suspicious scheduled tasks and persistent binaries.
In detection and cleaning it is important to go beyond the Joomla panel: it inspects public folders for new or altered PHP files, reviews the database for unusual entries in tables related to editor and profile settings, and analyzes web and application logs for mass profile creation patterns or automated requests. Useful indicators include new PHP endpoints, outgoing traffic to suspicious domains and persistent processes initiated from the web environment.
Organizations should also strengthen preventive controls: activate a WAF with rules that block PHP charges, implement file integrity detection, limit writing permissions in CMS directories, use strong authentication and carefully review any third party extension before installation. The automation of patches and an updated inventory of Joomla instances are measures that reduce window time vulnerable to public exploits.

For security equipment that manage multiple domains or customers, centralize monitoring and apply controlled intrusion tests can quickly reveal unpatched instances. The vulnerability scanning tools and the analysis of commitment indicators should be complemented by response procedures that include restoration from clean backups when forensic cleaning is not reliable.
Speed matters: when CISA qualifies a failure as "actively exploited," the probability of large-scale automated attacks is triggered. Keeping informed and acting with method - patching, detecting and, if necessary, recovering - is the only practical way to limit the damage. For more institutional context on the inclusion in the catalogue of exploited vulnerabilities, see the CISA entry on this case in its catalogue: CVE-2026-48907 in the CISA catalogue.
If you have no internal capacity for research or cleaning, consider hiring an incident response team with experience in web forensic and CMS; poor cleaning can leave open doors that allow reinfections. In all cases, document the actions taken and prepare a communication plan for users and customers if data or service commitment is confirmed.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...