# Joomla patches ten core vulnerabilities

Published: 2026-08-19 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/6fa4ea93-5afb-5a1c-96e2-b2698462be1d/joomla-patches-ten-core-vulnerabilities

> CERT-FR advises multiple Joomla! vulnerabilities allowing remote code execution, data integrity issues, and XSS, fixed in versions 5.4.8 and 6.1.3.

CERT-FR issued an advisory covering ten distinct vulnerabilities affecting Joomla! CMS versions 3.x through 5.x (prior to 5.4.8) and 6.x (prior to 6.1.3). The flaws span multiple weakness categories including improper access control (ACL) checks on webservice endpoints for categories, custom fields, and batch copy actions, a multi-factor authentication bypass, CORS origin validation issues, response header injection, unrestricted upload of .shtml files, and cross-site scripting through schema.org output injection.

Collectively these issues could allow an attacker to execute arbitrary code remotely, compromise data integrity, bypass security policies (including MFA), and conduct indirect remote code injection via XSS. Ten CVEs were assigned (CVE-2026-71572, -71573, -71574, -72531, -72532, -73336, -73337, -73371, -73372, -73373) corresponding to ten separate Joomla security bulletins published August 18, 2026. No active exploitation is mentioned in the advisory; administrators are directed to apply the vendor's patches referenced in the official Joomla security bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-71572, CVE-2026-71573, CVE-2026-71574, CVE-2026-72531, CVE-2026-72532, CVE-2026-73336, CVE-2026-73337, CVE-2026-73371, CVE-2026-73372, CVE-2026-73373

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1046

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6fa4ea93-5afb-5a1c-96e2-b2698462be1d/joomla-patches-ten-core-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
