Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploited Vulnerabilities in Joomla and LiteSpeed Uncovered

Exploited Vulnerabilities in Joomla and LiteSpeed Uncovered

Posted on June 17, 2026June 17, 2026 By CWS

Recent reports indicate that cyber attackers are exploiting vulnerabilities in Joomla and the LiteSpeed cPanel plugin, posing significant risks to users. These security flaws are being used for unauthorized code execution and privilege escalation, necessitating immediate attention and action from affected users.

Joomla Vulnerability Details

The first vulnerability, identified as CVE-2026-48907, affects the Joomla Content Editor (JCE). This flaw, stemming from improper access controls, allows unauthenticated individuals to upload arbitrary files onto servers, leading to the execution of unauthorized PHP code. All previous versions of JCE Pro before 2.9.99.5 are impacted.

Joomla addressed this security issue with a patch released on June 3, followed by additional protections in version 2.9.99.6 on June 6. Despite these efforts, Joomla warned that the vulnerability is actively being exploited in the wild, with automated attacks and publicly available exploit code making even non-public registration sites vulnerable.

Steps for Joomla Users

Joomla has strongly advised users to update their software to the latest versions to mitigate these risks. However, they caution that updating alone will not clean a site that has already been compromised. They have provided indicators of compromise (IoCs) to assist administrators in identifying and addressing any breaches.

LiteSpeed Plugin Vulnerability

Similarly, a vulnerability in the LiteSpeed user-end plugin for cPanel, CVE-2026-54420, has been identified. This UNIX Symbolic Link (symlink) following vulnerability allows users with FTP or web shell access to elevate their privileges to root on shared hosting servers.

The vulnerability affects all versions of the plugin before 2.4.8, released on June 1. Users are urged to update immediately and use the provided commands to check for any signs of compromise.

Both vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV) catalog by the US Cybersecurity and Infrastructure Security Agency (CISA). Federal agencies are required to apply patches by mid-June to prevent potential risks posed by these security weaknesses, which could lead to automated asset takeovers.

The ongoing exploitation of these vulnerabilities highlights the critical importance of timely software updates and vigilance in cybersecurity practices.

Security Week News Tags:CISA, CVE-2026-48907, CVE-2026-54420, cyber attacks, Cybersecurity, Exploit, Joomla, LiteSpeed, security patch, Vulnerabilities

Post navigation

Previous Post: Mastra npm Packages Compromised in Supply Chain Attack
Next Post: LiteLLM Flaw Allows Authentication Bypass via Host Header

Related Posts

SAP Addresses Major Security Flaws in NetWeaver and More SAP Addresses Major Security Flaws in NetWeaver and More Security Week News
BlackSanta Malware Disables Security Before Attack BlackSanta Malware Disables Security Before Attack Security Week News
‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices ‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices Security Week News
Palo Alto Networks Fixes Critical Security Flaws Palo Alto Networks Fixes Critical Security Flaws Security Week News
Adobe Patches Critical Code Execution Bugs Adobe Patches Critical Code Execution Bugs Security Week News
AI and Cybersecurity Updates: Major Breaches and Layoffs AI and Cybersecurity Updates: Major Breaches and Layoffs Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark