CISA orders feds to patch Joomla flaw
CISA told federal agencies to patch a max-severity flaw in the JCE Joomla plugin by Friday. The bug lets unauthenticated attackers upload and run PHP code.
CVE-2026-48907 is an improper access control issue in Widget Factory's JCE editor. It carries maximum severity and sits on CISA's actively exploited list with public exploit code already circulating.
Affects any Joomla site running the JCE plugin before version 2.9.99.5. Federal civilian agencies face the Friday deadline under binding directive.
JCE team released the fix in early June after seeing automated attacks hit sites without public registration.
