Joomla patches ten core vulnerabilities
CERT-FR advises multiple Joomla! vulnerabilities allowing remote code execution, data integrity issues, and XSS, fixed in versions 5.4.8 and 6.1.3.
CERT-FR issued an advisory covering ten distinct vulnerabilities affecting Joomla! CMS versions 3.x through 5.x (prior to 5.4.8) and 6.x (prior to 6.1.3). The flaws span multiple weakness categories including improper access control (ACL) checks on webservice endpoints for categories, custom fields, and batch copy actions, a multi-factor authentication bypass, CORS origin validation issues, response header injection, unrestricted upload of .shtml files, and cross-site scripting through schema.org output injection.
Collectively these issues could allow an attacker to execute arbitrary code remotely, compromise data integrity, bypass security policies (including MFA), and conduct indirect remote code injection via XSS. Ten CVEs were assigned (CVE-2026-71572, -71573, -71574, -72531, -72532, -73336, -73337, -73371, -73372, -73373) corresponding to ten separate Joomla security bulletins published August 18, 2026. No active exploitation is mentioned in the advisory; administrators are directed to apply the vendor's patches referenced in the official Joomla security bulletins.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1046
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free