Dossier
CVE-2026-48907
Coverage of CVE-2026-48907 in the Nexus archive.
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
CISA added a maximum-severity vulnerability in Joomla JCE to its KEV catalog, citing active exploitation. The flaw, CVE-2026-48907 with a CVSS score of 10.0, involves improper access control allowing arbitrary PHP code execution.