News - Security News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using AcyMailing 6.0.0 through 10.11.0 should update the extension to version 10.11.1 or later to remediate CVE-2026-56292, an unauthenticated SQL injection vulnerability. This advisory explains the confirmed Joomla scope, the official CVSS 4.0 rating, practical update steps, and the separate WordPress-only AcyMailing issue that agencies may also need to track.
Read more: AcyMailing Joomla SQL Injection: Update to 10.11.1 or Later
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using the Joomla Content Editor (JCE) extension should urgently check their installed version and update if it is earlier than 2.9.99.5. CVE-2026-48907 is a critical, actively exploited improper access control flaw that can permit unauthenticated remote code execution through the creation of editor profiles and PHP upload and execution.
Read more: Patch JCE Now for Actively Exploited CVE-2026-48907
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Eleven confirmed Joomla extension vulnerabilities disclosed around July 2026 affect popular page builders, forms, download managers, calendar tools and email extensions. Four are listed by CISA as known exploited vulnerabilities, making a complete extension inventory, prompt updates and post-update checks an immediate priority for site owners and agencies.
Read more: Joomla Extension Vulnerabilities: July 2026 Actions for Site Owners
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Proof-of-work CAPTCHA Joomla 6: learn what Joomla 6 adds, how to upgrade safely, developer notes, system checks and roadmap guidance for site owners.
Read more: Implement Privacy‑First Proof‑of‑Work CAPTCHAs in Joomla 6 (Step‑by‑Step)