Skip to content
The Nexus
SECURITYJun 17 · 05:50 UTCTHE HACKER NEWS[email protected] (The Hacker News)

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

CISA added a maximum-severity vulnerability in Joomla JCE to its KEV catalog, citing active exploitation. The flaw, CVE-2026-48907 with a CVSS score of 10.0, involves improper access control allowing arbitrary PHP code execution.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting