VORANT. Threat Intelligence Sign in Get the full feed

Joomla patches ten core vulnerabilities

routine vulnerability technology

CERT-FR advises multiple Joomla! vulnerabilities allowing remote code execution, data integrity issues, and XSS, fixed in versions 5.4.8 and 6.1.3.

CERT-FR issued an advisory covering ten distinct vulnerabilities affecting Joomla! CMS versions 3.x through 5.x (prior to 5.4.8) and 6.x (prior to 6.1.3). The flaws span multiple weakness categories including improper access control (ACL) checks on webservice endpoints for categories, custom fields, and batch copy actions, a multi-factor authentication bypass, CORS origin validation issues, response header injection, unrestricted upload of .shtml files, and cross-site scripting through schema.org output injection.

Collectively these issues could allow an attacker to execute arbitrary code remotely, compromise data integrity, bypass security policies (including MFA), and conduct indirect remote code injection via XSS. Ten CVEs were assigned (CVE-2026-71572, -71573, -71574, -72531, -72532, -73336, -73337, -73371, -73372, -73373) corresponding to ten separate Joomla security bulletins published August 18, 2026. No active exploitation is mentioned in the advisory; administrators are directed to apply the vendor's patches referenced in the official Joomla security bulletins.

Mentioned in this report

Vulnerabilities CVE-2026-71572CVE-2026-71573CVE-2026-71574CVE-2026-72531CVE-2026-72532CVE-2026-73336CVE-2026-73337CVE-2026-73371CVE-2026-73372CVE-2026-73373

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1046

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free