U.S. CISA adds Widget Factory Joomla Content Editor (JCE) flaw to its Known Exploited Vulnerabilities catalog


U.S. CISA adds Widget Factory Joomla Content Editor flaw to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
June 17, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Widget Factory Joomla Content Editor (JCE) flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Widget Factory Joomla Content Editor (JCE) flaw, tracked as CVE-2026-48907 (CVSS score of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog.

“A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.” reads the advisory.

The vulnerability allows attackers to create new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

“Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.” states CISA.

The vulnerability impacts JCE versions 1.0.0 through 2.9.99.4, it was fixed in version 2.9.99.5, released on June 3, 2026. At this time, details of ongoing attacks have not been disclosed.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on June 19, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Ahead of WWDC starting on June 8, Apple has sent out invites to the media for the event, as well as outlining its main schedule for the week.

Apple’s Worldwide Developer Conference is the big event for developers working in the Apple ecosystem. The 2026 edition is sure to be exciting as usual, and the company is preparing to get people involved.

On Monday, Apple started sending out invitations to members of the media to attend a special event at Apple Park. While this would previously have involved watching a live keynote, it has since taken the form of a mass viewing of the keynote at Apple’s headquarters, along with special events for attendees.

The tagline for the event this time is “Coming bright up.” As usual, it is a cryptic statement, providing little clue about what Apple will ultimately reveal to the world.

A schedule to follow

At the same time as sending out invitations, Apple has also listed the events that will take part across the week. It also outlined how developers can observe and take part in events remotely.

The week starts with the Apple Keynote on June 8 at 10 a.m. PDT, which will be the venue for Apple’s main launches, such as iOS 27. The keynote will stream from Apple’s website, the Apple TV app, and the Apple YouTube channel.

At 1 p.m. later that day, the Platforms State of the Union will be a deeper dive into new features, APIs, and technologies that are on the way. It will be viewable from the Apple Developer app, website, YouTube channel, and Bilibili.

Throughout the week, Apple will be holding video sessions and releasing guides, hosted by Apple engineers and designers. Group Labs, consisting of live online presentations and Q&A sessions, will also take place from Tuesday through Friday.

There will also be the Apple Design Awards, with 36 finalists chosen to highlight the craft, creativity, and technical expertise of the developer community.



Source link