The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are actively exploiting two critical vulnerabilities in popular Joomla extensions. Both flaws allow arbitrary file uploads that can lead to remote code execution (RCE). Because the vulnerabilities are already being exploited, CISA has added them to its Known Exploited Vulnerabilities (KEV) catalog and…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a critical Joomla vulnerability by Friday after attackers began exploiting the flaw. The agency added the issue to its Known Exploited Vulnerabilities catalog, which tracks security flaws that attackers actively use in real-world attacks. The vulnerability, tracked as CVE-2026-48907, affects the…