CVE-2026-48907
-
CISA warns of actively exploited Joomla editor flaw rated maximum severity
CISA added a maximum-severity Joomla content editor flaw to its known exploited vulnerabilities list, citing active abuse. The bug affects JCE versions up to 2.9.99.4 and was fixed in June 2026.

