Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Joomla JCE Vulnerability Exploited for PHP Code Execution

Joomla JCE Vulnerability Exploited for PHP Code Execution

Posted on June 17, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a severe vulnerability in the Widget Factory Joomla Content Editor (JCE). This flaw has been actively exploited and has been included in CISA’s Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is identified as CVE-2026-48907, with a maximum CVSS score of 10.0, indicating its critical nature.

Critical Security Flaw Details

The vulnerability stems from improper access control within the Joomla Content Editor, permitting unauthorized users to create new editor profiles. This loophole allows for the upload and execution of PHP code, posing a significant security threat. Versions 1.0.0 through 2.9.99.4 of the JCE are affected, with a patch available in version 2.9.99.5 as of June 3, 2026.

CISA has urged Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches by June 19, 2026, to mitigate the risk. Despite the urgency, details about the specific exploitation methods remain undisclosed.

WordPress Sites Under Attack

Simultaneously, a new supply chain attack has been identified, targeting over a million WordPress sites. The attack focuses on plugins such as OptinMonster, TrustPulse, and PushEngage, where attackers inject malicious JavaScript. This code activates when an admin is logged in, creating a backdoor admin account and installing a hidden plugin.

Another campaign involves embedding a fake WordPress plugin called “Beloved PBN Entegrasyonu”. This plugin stealthily communicates with an external API and injects unauthorized HTML or JavaScript into the site, compromising its integrity.

Impact and Future Outlook

These security breaches allow attackers to gain extensive control over compromised sites, including file manipulation and server access without authentication. Such vulnerabilities not only threaten site security but also impact SEO rankings, as noted by Sucuri researcher Puja Srivastava. The injected outbound links can lead to penalties from Google, damaging the site’s visibility.

The campaigns, believed to be operated by Turkish-speaking threat actors, utilize hidden backlinks for Private Blog Networks (PBNs), likely connected to gambling and adult content niches. As these threats evolve, cybersecurity measures and prompt patching remain crucial in safeguarding digital assets.

The Hacker News Tags:Backdoor, CISA, Cybersecurity, Joomla, Malware, PBN, PHP code execution, SEO, supply chain attack, Threat Actors, Vulnerability, WordPress

Post navigation

Previous Post: Hackers Exploit AI Tools for Advanced Cyber Attacks
Next Post: Fortinet Vulnerabilities Exploited by Hackers

Related Posts

Apple Patches WebKit Flaw in iOS and macOS Apple Patches WebKit Flaw in iOS and macOS The Hacker News
Critical Flaw in LMS Exploited for Cyber Attacks Critical Flaw in LMS Exploited for Cyber Attacks The Hacker News
CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack The Hacker News
U.S. DoJ Seizes Fraud Domain Behind .6 Million Bank Account Takeover Scheme U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme The Hacker News
Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools The Hacker News
5 Ways Identity-based Attacks Are Breaching Retail 5 Ways Identity-based Attacks Are Breaching Retail The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Oracle Releases June Security Patch with 245 Fixes
  • LiteLLM Flaw Allows Authentication Bypass via Host Header
  • Exploited Vulnerabilities in Joomla and LiteSpeed Uncovered
  • Mastra npm Packages Compromised in Supply Chain Attack
  • AIRecon Revolutionizes Offline Penetration Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Oracle Releases June Security Patch with 245 Fixes
  • LiteLLM Flaw Allows Authentication Bypass via Host Header
  • Exploited Vulnerabilities in Joomla and LiteSpeed Uncovered
  • Mastra npm Packages Compromised in Supply Chain Attack
  • AIRecon Revolutionizes Offline Penetration Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark