CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
CISA warns of a maximum-severity security flaw in Joomla JCE, allowing PHP code execution. The vulnerability is being actively exploited.
Intelligence analysis by Llama 3.3 70B

A security flaw in Joomla JCE is being exploited, allowing arbitrary code execution. CISA has added the flaw to its Known Exploited Vulnerabilities catalog.
A security flaw in a popular website editor called Joomla JCE is being exploited by hackers. This means they can run bad code on websites that use it, which is very dangerous. The people who make Joomla JCE have fixed the problem, but users need to update their software to stay safe.
Analysis
Introduction to the Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of a maximum-severity security flaw in the Widget Factory Joomla Content Editor (JCE). The vulnerability, tracked as CVE-2026-48907, is a case of improper access control that could facilitate arbitrary code execution. This means that attackers could potentially upload and execute malicious PHP code on vulnerable systems.
Impact of the Vulnerability
The vulnerability impacts JCE versions from 1.0.0 through 2.9.99.4. It has been patched in version 2.9.99.5, released on June 3, 2026. Federal Civilian Executive Branch (FCEB) agencies have been ordered to apply the fixes by June 19, 2026. The vulnerability is being actively exploited, although there is currently no information on how it is being exploited in the wild.
Broader Context of Supply Chain Attacks
The disclosure of this vulnerability comes as Sansec detailed a new supply chain attack campaign that targeted over 1 million sites using OptinMonster, TrustPulse, and PushEngage WordPress plugins. In this campaign, threat actors injected malicious JavaScript that waited for a logged-in administrator, created a backdoor admin account, and installed a self-hiding backdoor plugin. This highlights the growing threat of supply chain attacks, where vulnerabilities in third-party components are exploited to gain access to sensitive systems.
Key points
- A security flaw in Joomla JCE is being exploited, allowing arbitrary code execution
- The vulnerability is being actively exploited, although there is no information on how it is being exploited
- Federal Civilian Executive Branch agencies have been ordered to apply the fixes by June 19, 2026
If users patch the vulnerability quickly, they can prevent attackers from exploiting it. Additionally, the fact that CISA is warning about the vulnerability highlights the importance of cybersecurity and the need for users to stay vigilant.
The vulnerability is being actively exploited, which means that attackers may have already gained access to sensitive systems. Additionally, the fact that the vulnerability is in a third-party component highlights the risks of supply chain attacks, which can be difficult to defend against.



