The most serious Joomla story of the moment: the popular editor JCE (Joomla Content Editor, component com_jce ) has vulnerability CVE-2026-48907 (CVSS 10.0) — unauthenticated remote code execution (RCE) . An attacker without a single password creates a malicious profile through profiles.import function and uploads and executes PHP on the server. The vulnerability is on the CISA KEV list , and the attacks are automated — web shells, miners and defacement.
Have you been hit? Clues to check
- Unknown JCE profiles with strange names, e.g.
J940401orPwned, sometimes with the sequence-99999 - Foreign PHP files in
/images/, such asjce_5f314aa0.phpor.php.gif - In the logs, requests to
index.php?option=com_jce&task=profiles.import - Subtle content, redirects or sudden server load
What to do now
- Update JCE to version 2.9.99.5 or later (patch 6/3/2026).
- Review and delete unknown JCE profiles and suspicious PHP files in
/images/. - Check for backdoors and unknown Super User accounts; change all passwords.
- Block PHP execution in
images/andmedia/at the server level.
JCE has been a target of attackers for years (and the old plugin.rpc upload flaw still plagues unpatched installations), so make updating this editor a priority.
Do you have Joomla with JCE editor and suspect a breach? Send us the link — diagnosis is free, and we'll get back to you within 5 minutes. Emergency repair →
WMD — Super fast support.