SECURITYTHE HACKER NEWS
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
CISA added a maximum-severity vulnerability in Joomla JCE to its KEV catalog, citing active exploitation. The flaw, CVE-2026-48907 with a CVSS score of 10.0, involves improper access control allowing arbitrary PHP code execution.
Mentioned
Related Signal
Adjacent reporting
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
- Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
- CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
- CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV