Current Joomla vulnerabilities and the versions to update

A concise technical list for Joomla owners and administrators, based on confirmed affected versions, fixes and primary-source data. An update closes the known entry point but does not remove an existing backdoor.

3 CVEsconfirmed
Highupdate priority
12 Aug 2026last reviewed

Verified vulnerabilities

Compare the installed version and close the known entry point first.

ComponentAffectedActionStatusVerification
JCE
CVE-2026-48907
up to 2.9.99.4Update to 2.9.99.9 or newerActively exploitedVerified
SP Page Builder
CVE-2026-48908
up to 6.6.1Update to 6.6.2 or newerActively exploitedVerified
Helix3
CVE-2026-49049
up to 3.1.1Update both plugins to 3.1.2 or newerMass attacks reportedVerified

What to do first

  1. Preserve a copy of the files, database and access logs before cleanup.
  2. Isolate the site or place it in a safe maintenance mode.
  3. Update the vulnerable component, then inspect files, database records, users and persistence points.
  4. Rotate access credentials and recheck the site after 24 hours and 7 days.

Direct answers

Is Helix3 3.1.1 safe?

NVD lists versions through 3.1.1 as affected. Update both Helix3 plugins to 3.1.2 or later.

Does an update remove malware that is already installed?

No. An update closes the entry point. Existing web shells, rogue administrators and database injections require a separate investigation and cleanup.

Why can a file scanner miss AntonKill?

In the Helix3 wave the injected code can live in template parameters in the database. A clean filesystem scan is therefore not proof that the site is clean.

How the data is checked

Only confirmed CVEs, vendor guidance and public cybersecurity advisories are included. The review date is shown on this page, and the table is updated when recommendations change.

NVD CVE databaseVendor guidanceCERT advisories

Already hacked or did the update not help?

An update closes the vulnerability but does not remove backdoors, unknown administrators or database injections. Preserve a copy and access logs before cleanup.

Telegram