<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Joomla on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/joomla/</link><description>Recent content in Joomla on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 17 Jun 2026 05:50:46 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/joomla/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48907: Joomla JCE RCE Flaw Actively Exploited</title><link>https://zxcloudsecurity.co.uk/posts/joomla-jce-rce-cve-2026-48907-actively-exploited-cisa-kev/</link><pubDate>Wed, 17 Jun 2026 05:50:46 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/joomla-jce-rce-cve-2026-48907-actively-exploited-cisa-kev/</guid><description>CISA adds CVE-2026-48907 (CVSS 10.0) to KEV catalogue. The Joomla JCE plugin flaw allows arbitrary PHP code execution — patch immediately.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html">The Hacker News</a></p>
<hr>
<p>A critical vulnerability (CVE-2026-48907, CVSS 10.0) in the Joomla Content Editor (JCE) plugin allows attackers to bypass access controls and execute arbitrary PHP code on affected servers. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Any internet-facing Joomla site running the JCE plugin is at serious risk of full server compromise.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Immediately audit your estate and cloud-hosted workloads for any Joomla installations running the JCE plugin and apply the vendor patch as an emergency change. If patching cannot be done promptly, take affected instances offline or block public access to the Joomla admin and editor endpoints via WAF or security group rules.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html">CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution</a></p>
]]></content:encoded></item><item><title>CVE-2026-48907: Joomla Plugin RCE via File Upload</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-48907-widget-factory-joomla-content-editor-rce/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-48907-widget-factory-joomla-content-editor-rce/</guid><description>CVE-2026-48907 allows unauthenticated attackers to upload and execute PHP code via Widget Factory Joomla Content Editor. Patch by 19 June 2026.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities</a></p>
<hr>
<p>A critical vulnerability in the Widget Factory Joomla Content Editor plugin allows unauthenticated attackers to upload and execute arbitrary PHP code by creating new editor profiles. This effectively grants full remote code execution on affected Joomla sites without requiring any login credentials. It has been added to the CISA Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit all Joomla deployments across your environment and patch or disable the Widget Factory Content Editor plugin immediately. If Joomla sites are hosted on cloud infrastructure, treat any exposed instance as potentially compromised and review web application firewall rules to block unauthenticated POST requests to editor profile creation endpoints whilst patching is carried out.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CVE-2026-48907: Widget Factory Joomla Content Editor </a></p>
]]></content:encoded></item></channel></rss>