Current Joomla vulnerabilities and the versions to update
A concise technical list for Joomla owners and administrators, based on confirmed affected versions, fixes and primary-source data. An update closes the known entry point but does not remove an existing backdoor.
Verified vulnerabilities
Compare the installed version and close the known entry point first.
| Component | Affected | Action | Status | Verification |
|---|---|---|---|---|
JCECVE-2026-48907 | up to 2.9.99.4 | Update to 2.9.99.9 or newer | Actively exploited | Verified |
SP Page BuilderCVE-2026-48908 | up to 6.6.1 | Update to 6.6.2 or newer | Actively exploited | Verified |
Helix3CVE-2026-49049 | up to 3.1.1 | Update both plugins to 3.1.2 or newer | Mass attacks reported | Verified |
What to do first
- Preserve a copy of the files, database and access logs before cleanup.
- Isolate the site or place it in a safe maintenance mode.
- Update the vulnerable component, then inspect files, database records, users and persistence points.
- Rotate access credentials and recheck the site after 24 hours and 7 days.
Direct answers
Is Helix3 3.1.1 safe?
NVD lists versions through 3.1.1 as affected. Update both Helix3 plugins to 3.1.2 or later.
Does an update remove malware that is already installed?
No. An update closes the entry point. Existing web shells, rogue administrators and database injections require a separate investigation and cleanup.
Why can a file scanner miss AntonKill?
In the Helix3 wave the injected code can live in template parameters in the database. A clean filesystem scan is therefore not proof that the site is clean.
How the data is checked
Only confirmed CVEs, vendor guidance and public cybersecurity advisories are included. The review date is shown on this page, and the table is updated when recommendations change.
Already hacked or did the update not help?
An update closes the vulnerability but does not remove backdoors, unknown administrators or database injections. Preserve a copy and access logs before cleanup.