CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

Image for article CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
News Source : Internet

News Summary

  • The u.s. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw to its Known Exploited Vulnerabilities (KEV) catalog.
  • The vulnerability, tracked as CVE-2026-48907 (CVSS score: 10.0), is a case of improper access control that could facilitate arbitrary code execution.
  • The disclosure comes as Sansec detailed a new supply chain attack campaign that targeted over 1 million sites using OptinMonster, TrustPulse, and PushEngage WordPress plugins.
The U.S.

Must read Articles