The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three maximum-severity vulnerabilities in popular Joomla extensions to its Known Exploited Vulnerabilities (KEV) catalog. With federal agencies ordered to patch by July 10 and attack automation already in full swing, any organization running Joomla with these extensions needs to act immediately.
The vulnerabilities affect SP Page Builder by JoomShaper, Page Builder CK by Joomlack, and the JCE (Joomla Content Editor) by Widget Factory. All three allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable servers. Working exploit code is public and automated attacks have been observed in the wild.
Vulnerability Details
CVE-2026-56290: Page Builder CK (CVSS 9.8)
Page Builder CK by Joomlack contains an unauthenticated arbitrary file upload vulnerability. Attackers can upload executable PHP files to the web root without any authentication, leading to full remote code execution on the underlying server.
Affected versions: All versions before 3.6.0 Fix: Update to Page Builder CK 3.6.0 (released June 27, 2026) Exploitation: Within hours of the patch release, threat actors began targeting the vulnerability to deploy web shells on unpatched sites.
CVE-2026-48907: JCE Editor by Widget Factory (CVSS 9.8)
The Joomla Content Editor (JCE) plugin by Widget Factory contains an improper access control vulnerability. Unauthenticated users can create new editor profiles, which ultimately allows them to upload and execute PHP code on the server.
Affected versions: All versions before 2.9.99.6 Fix: Update to JCE 2.9.99.6 (patched in early June 2026) Exploitation: Working exploit code is public and attacks are fully automated. The JCE team warns that even sites without public registration are not safe.
SP Page Builder by JoomShaper (CVSS 10.0)
The SP Page Builder extension suffers from an improper access control vulnerability in its custom icon upload feature. This feature is reachable without authentication and writes files to the web root folder, where PHP execution is typically enabled.
Affected versions: All versions before 6.6.2 Fix: Update to SP Page Builder 6.6.2 Exploitation: Attackers are planting hidden administrator accounts on Joomla websites and deploying PHP file manager backdoors for persistent access.
Impact Assessment
The combined impact of these vulnerabilities is severe. An attacker exploiting any of the three flaws gains:
- Full remote code execution on the web server
- Persistence through hidden admin accounts and web shells
- Lateral movement potential into connected databases and networks
- Data exfiltration capabilities from compromised sites
Researchers have confirmed that all three vulnerabilities are being actively exploited in coordinated campaigns. CISA has observed attackers chaining the SP Page Builder flaw with post-exploitation tooling to establish long-term access.
Affected Systems
Any Joomla website running one or more of these extensions is at immediate risk:
- SP Page Builder by JoomShaper (versions before 6.6.2)
- Page Builder CK by Joomlack (versions before 3.6.0)
- JCE Editor by Widget Factory (versions before 2.9.99.6)
CISA estimates that tens of thousands of Joomla sites globally use these plugins, with a significant portion still running vulnerable versions.
Mitigation and Patching
Immediate steps (do these today)
-
Update affected extensions immediately:
- SP Page Builder: upgrade to version 6.6.2 or later
- Page Builder CK: upgrade to version 3.6.0 or later
- JCE Editor: upgrade to version 2.9.99.6 or later
-
If already compromised, follow this clean-up procedure:
- Back up any rogue editor profiles or suspicious admin accounts for forensic investigation
- Update the extensions to the patched versions
- Delete any attacker-created profiles, accounts, or files
- Change ALL passwords: administrator account, database credentials, and hosting account
- Run a full server-side malware scan
-
Post-remediation verification:
- Audit all administrator accounts for unauthorized additions
- Review file system for unexpected PHP files in web-accessible directories
- Check database for suspicious entries in extension tables
- Monitor access logs for unusual POST requests to upload endpoints
Important note
Updating the extensions closes the entry point but does not clean a site that was already compromised. If your site was hit before you patched, the update alone will not remove what the attacker left behind. Full remediation requires the clean-up steps above.
Frequently Asked Questions
Q: Do I need to be running a specific Joomla version to be vulnerable? A: These vulnerabilities are in the extensions, not Joomla core. Any Joomla version running the affected extensions is vulnerable regardless of the CMS version.
Q: Is my site safe if I don't allow user registration? A: No. All three flaws are exploitable without any authentication. The JCE team explicitly warns that "a site with no public registration is not safe."
Q: How quickly should I patch? A: Immediately. CISA has ordered federal agencies to patch by July 10. For non-federal organizations, the same urgency applies -- exploit code is public and attacks are automated.
Q: Can these vulnerabilities be detected with a WAF? A: Partially. A Web Application Firewall may detect some exploitation attempts, but it is not a substitute for patching. The SP Page Builder flaw uses the legitimate icon upload functionality, which is harder to block without breaking legitimate use.
Q: I use a different page builder. Am I affected? A: Only the three specific extensions listed are confirmed as exploited. However, this is a good time to audit all installed Joomla extensions for unnecessary plugins and ensure everything is up to date.
Key Takeaways
- Three critical Joomla extension CVEs (CVSS 9.8-10.0) are under active exploitation
- CISA has added all three to the KEV catalog with a July 10 patch deadline
- All three allow unauthenticated remote code execution
- Working exploit code is public and attacks are fully automated
- Updating alone is not enough for already-compromised sites
- Audit admin accounts, files, and logs after patching
Conclusion
The coordinated exploitation of these three Joomla extension vulnerabilities represents a serious threat to the Joomla ecosystem. With maximum-severity CVSS scores, publicly available exploit code, and automated attack campaigns, every Joomla site operator should treat this as an emergency patching situation. The July 10 CISA deadline applies to US federal agencies, but the risk is universal.
Patch now, audit your site for signs of compromise, and ensure your entire extension inventory is kept current. In the current threat landscape, unpatched Joomla extensions are one of the fastest paths to a full server takeover.
Sources: SecurityWeek, BleepingComputer, NVD, CISA KEV
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.