CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
News Source : Internet
News Summary
- The u.s. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw to its Known Exploited Vulnerabilities (KEV) catalog.
- The vulnerability, tracked as CVE-2026-48907 (CVSS score: 10.0), is a case of improper access control that could facilitate arbitrary code execution.
- The disclosure comes as Sansec detailed a new supply chain attack campaign that targeted over 1 million sites using OptinMonster, TrustPulse, and PushEngage WordPress plugins.
The U.S.
Never miss a story from us, subscribe to our newsletter