News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
The Joomla message “Offered update has expired” can interrupt a routine core update, but the available evidence indicates that it is an update-state, metadata, or timing condition—not a separately tracked security vulnerability. This guide explains how to respond calmly, protect the site before retrying, and decide when to seek confirmation through official Joomla channels.
Read more: Joomla Offered Update Has Expired: Meaning and Safe Next Steps
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
The JCE profiles hack refers to CVE-2026-48907, an actively exploited Joomla extension vulnerability that can let unauthenticated attackers create editor profiles and ultimately upload and execute PHP code. Joomla administrators should update affected JCE installations, assess sites for unauthorised profiles and suspicious uploads, and treat patching as only the first stage of remediation.
Read more: How to Detect and Clean the JCE Profiles Hack on Joomla Sites
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Quix Page Builder Pro versions 1.0 through 6.2.0 are affected by CVE-2026-58078, an unauthenticated SQL injection vulnerability. Joomla administrators should update to Quix 6.2.1 or later, assess potentially exposed data, and check their wider extension inventory for related SQL injection risks.
Read more: Quix Page Builder SQL Injection: Update to 6.2.1 Now
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Two confirmed Joomla extension vulnerabilities require prompt action: CVE-2026-57833 affects AcyMailing and CVE-2026-58077 affects EDocman. Administrators should identify affected installations, update AcyMailing to 10.11.1 or later and EDocman to 3.9.0 or later, then assess whether publicly exposed sites may have disclosed database data.
Read more: Patch AcyMailing and EDocman for Two Joomla SQL Injection CVEs