CISA ordered federal agencies to patch CVE-2026-48907, a maximum-severity flaw in the Widget Factory Joomla Content Editor plugin, by Friday. The vulnerability allows unauthenticated code execution and is actively exploited with public exploit code. JCE Pro 2.9.99.6 fixes the issue.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
CISA Adds CVE-2026-48907 to KEV Catalog for Joomla JCE