Security
CISA mandates patch for exploited Joomla plugin flaw
CISA has ordered federal agencies to patch a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin, tracked as CVE-2026-48907, which is being actively exploited. The flaw allows unauthenticated attackers to execute code on Joomla sites using the plugin.