Joomla vulnerabilities 2026: which extensions are under active attack

Joomla was not attacked through its core in 2026, but through extensions with publicly reachable upload endpoints. Within a few weeks several flaws with the highest possible severity piled up – four of them are listed by the US agency CISA as confirmed actively exploited.

What makes them dangerous: these flaws need no login and no password. An automated scanner finds the site, uploads a PHP file and runs it. That is why small sites nobody would target deliberately were hit just as hard.

Below you will find the affected and the safe versions for each extension. If your site already shows symptoms, this overview will not be enough – then it is about clean-up.

  • Information as of July 2026, based on NVD, CISA KEV and the vendor advisories
  • specialised in Joomla, not WordPress with Joomla on the side
  • initial assessment free of charge, even if you only want to know whether you are affected
Free assessment

The affected extensions at a glance

What matters is not the name of the flaw but the version number installed on your site. You find it in the backend under System, Manage, Extensions.

JCE Editor – safe from 2.9.99.5

CVE-2026-48907, severity 10.0 out of 10. All versions from 1.0.0 to 2.9.99.4 are affected, Free and Pro. The profile import allowed editor profiles to be created without authentication, and through them PHP files could be uploaded and executed. 2.9.99.9 is recommended because it adds further hardening.

SP Page Builder – safe from 6.6.2

CVE-2026-48908, severity 10.0 out of 10, listed by CISA as actively exploited. All versions up to and including 6.6.1 are affected. The custom icon upload checked neither authentication nor file type, so a PHP file could land in a publicly reachable directory and run immediately.

Helix Ultimate – safe from 2.2.7

CVE-2026-57829 and CVE-2026-57830, severities 8.7 and 8.8. All versions from 1.0 to 2.2.6 are affected. Several AJAX actions ran without login, permission or CSRF checks. Important: both the template and the system plugin need updating, and 2.2.8 is recommended.

iCagenda – safe from 3.9.15 or 4.0.8

CVE-2026-48939, severity 10.0 out of 10, listed by CISA as actively exploited. Affected are the 3.x branch from 3.2.1 up to before 3.9.15 and the 4.x branch from 4.0.0 up to before 4.0.8. Here too an unauthenticated upload led to PHP code execution.

Page Builder CK – safe from 3.6.0

CVE-2026-56290, severity 10.0 out of 10, listed by CISA as actively exploited. All versions before 3.6.0 are affected. Same pattern: file upload without authentication, followed by code execution on the server.

Balbooa Forms – safe from 2.4.1

CVE-2026-56291, severity 10.0 out of 10, listed by CISA as actively exploited. All versions before 2.4.1 are affected. Form uploads without an authentication check, with the same outcome as in the other cases.

Details on the three most common cases

JCE, SP Page Builder and Helix Ultimate are present in a very large share of Joomla installations. For these three we have written up how the flaw works, how to check your version and how to spot a break-in:

JCE vulnerability: check, patch, spot the traces
SP Page Builder: critical flaw in the icon upload
Helix Ultimate: update template and plugin together

Updating is not enough once the break-in has happened

An update closes the door. It does not remove what came in beforehand. So if you ran a vulnerable version for weeks, do both: patch and check. The order matters – patch first, otherwise the automated attack simply restores whatever you removed.

  • look for super users in the backend that you did not create – addresses ending in @secure.local are a very reliable sign
  • look for PHP files in image and upload folders where they have no business being
  • for JCE, also review the editor profiles and preserve a copy of any profile you do not recognise before deleting it
  • check the host access logs for unusual POST requests to the affected components
  • rotate all passwords, database credentials and secrets if you find any traces

Why this wave hit so many small websites

It helps to picture how the attackers work: nobody picked your site. Automated scanners work through public lists of Joomla installations and try the known endpoints. Because these flaws need no login, the installed version number alone decides the outcome. A club or company website with no particular profile is therefore just as exposed as a large portal – and sites whose updates have been pending for months are the easiest targets.

We deliberately take on a limited number of ongoing Joomla projects so that quality, personal guidance and reliable response times stay intact.

FAQ

How do I find out which version is installed?

In the Joomla backend under System, then Manage, then Extensions. Search for the name of the extension and you will see the installed version. If you no longer have access, the files can be reached via your host and we will help with the assessment.

I updated in time. Do I still need to check?

If you updated within a few days of the release, the risk is low. If more time passed between the release and your update, it is worth reviewing user accounts and upload folders – in some cases the scanners were active within hours.

Is disabling the affected extension enough?

Usually not. Disabling leaves the files on the server and some endpoints remain reachable. Update to the safe version or uninstall the extension completely.

My Joomla version is old and the update will not install. What now?

That happens fairly often, usually because of an outdated PHP or Joomla version. For JCE the vendor offers a free patch package for older branches that closes the flaw without a full update. That is a stopgap, though – talk to us and we will work out the sensible path.

My site is already affected. What does clean-up cost?

€490 plus VAT in a standard case, meaning one Joomla installation with access available. The initial assessment is free. Your content stays intact and we do not need an old backup.

Can you make sure this does not happen again?

That is exactly what our care packages are for. Under Manage Joomla Care we close critical vulnerabilities immediately rather than in the next cycle – during this wave that was the difference between a same-day update and a break-in.

Not sure whether your site is affected? Send us the domain. You will get a free assessment of which affected extensions are running on your site and whether there are signs of a break-in.

Free assessment