News - Security News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
CVE-2026-48939 is a critical iCagenda file-upload vulnerability that can result in PHP code execution on affected Joomla sites. Administrators should upgrade the extension immediately, then investigate for signs of unauthorised uploads or execution because the flaw is listed in CISA’s Known Exploited Vulnerabilities catalog.
Read more: Critical iCagenda File Upload RCE: Patch CVE-2026-48939 Now
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
The Joomla message “Offered update has expired” can interrupt a routine core update, but the available evidence indicates that it is an update-state, metadata, or timing condition—not a separately tracked security vulnerability. This guide explains how to respond calmly, protect the site before retrying, and decide when to seek confirmation through official Joomla channels.
Read more: Joomla Offered Update Has Expired: Meaning and Safe Next Steps
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
The JCE profiles hack refers to CVE-2026-48907, an actively exploited Joomla extension vulnerability that can let unauthenticated attackers create editor profiles and ultimately upload and execute PHP code. Joomla administrators should update affected JCE installations, assess sites for unauthorised profiles and suspicious uploads, and treat patching as only the first stage of remediation.
Read more: How to Detect and Clean the JCE Profiles Hack on Joomla Sites
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Quix Page Builder Pro versions 1.0 through 6.2.0 are affected by CVE-2026-58078, an unauthenticated SQL injection vulnerability. Joomla administrators should update to Quix 6.2.1 or later, assess potentially exposed data, and check their wider extension inventory for related SQL injection risks.
Read more: Quix Page Builder SQL Injection: Update to 6.2.1 Now