DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-48907PUBLISHED: 2026-06-03
CRITICALCVE-2026-48907★ CISA KEV LISTED

Joomla JCE Editor Unauthenticated RCE via Profile Import

VENDOR: Widget Factory//PRODUCT: Joomla Content Editor (JCE)
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

An improper access control flaw (CWE-284) in the JCE profile import handler allows fully unauthenticated attackers to create rogue editor profiles, enabling arbitrary PHP file upload and execution via a three-request attack chain. Active exploitation has been confirmed with web shells observed in the wild; CISA added it to KEV on June 16, 2026 with a three-day federal remediation deadline. Public PoC code from YesWeHack and nuclei templates are publicly available on GitHub, and automated scanning has been observed at scale since the PoC dropped.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSJCE versions 1.0.0 through 2.9.99.4; fixed in 2.9.99.5 (June 3, 2026), hardened in 2.9.99.7
  • https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites
  • https://www.cisa.gov/news-events/alerts/2026/06/16/cisa-adds-one-known-exploited-vulnerability-catalog
  • https://www.yeswehack.com/news/rce-joomla-content-editor-extension
  • https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html
  • https://nvd.nist.gov/vuln/detail/CVE-2026-48907
SHARE BRIEF:✕ Post on Xin Share on LinkedIn