Current Joomla vulnerabilities and the versions to update
A concise technical list for Joomla owners and administrators, based on confirmed affected versions, fixes and primary-source data. An update closes the known entry point but does not remove an existing backdoor.
Verified vulnerabilities
Compare the installed version and close the known entry point first.
| Component | Affected | Action | Status | Verification |
|---|---|---|---|---|
JCECVE-2026-48907 | up to 2.9.99.4 | Update to 2.9.99.9 or newer | Actively exploited | Verified |
SP Page BuilderCVE-2026-48908 | up to 6.6.1 | Update to 6.6.2 or newer | Actively exploited | Verified |
Helix3CVE-2026-49049 | up to 3.1.1 | Update both plugins to 3.1.2 or newer | Mass attacks reported | Verified |
ZOOCVE-2026-74803CVE-2026-74804CVE-2026-75114CVE-2026-76610CVE-2026-76611CVE-2026-76612CVE-2026-77028CVE-2026-77029 | 1.0.0-4.1.63 for 74803/74804; additional fixes followed | Update to 4.1.66 or newer | Critical patch | Vendor changelog |
YOOtheme ProCVE-2026-75115CVE-2026-76613 | vendor lists the fixes in version 5.0.41 | Update to 5.0.41 or newer | Security patch | Vendor changelog |
21 August YOOtheme security updates
Install the latest vendor packages even if Joomla does not yet show an update notification.
ZOO 4.1.66 includes the earlier fixes for unauthenticated arbitrary file upload (CVE-2026-74803) and unauthenticated SQL injection (CVE-2026-74804), plus additional path traversal, XSS, redirect and CSRF fixes. Use the ZOO vendor changelog as the version source.
Detailed ZOO 4.1.66 response guide: CVE-2026-74803 and CVE-2026-74804.
YOOtheme Pro 5.0.41 fixes an arbitrary file-read issue and SQL injection available to contributor-level users. Verify the installed version after updating and review accounts with content-editing access. See the YOOtheme Pro vendor changelog.
Detailed YOOtheme Pro 5.0.41 response guide: CVE-2026-75115 and CVE-2026-76613.
If ZOO frontend submissions were exposed before patching, preserve logs before cleanup and inspect uploaded files, unexpected administrator accounts, modified PHP or JavaScript and scheduled tasks. Updating closes the documented code paths; it does not prove that an internet-facing site was not reached earlier.
What to do first
- Preserve a copy of the files, database and access logs before cleanup.
- Isolate the site or place it in a safe maintenance mode.
- Update the vulnerable component, then inspect files, database records, users and persistence points.
- Rotate access credentials and recheck the site after 24 hours and 7 days.
Direct answers
Is Helix3 3.1.1 safe?
NVD lists versions through 3.1.1 as affected. Update both Helix3 plugins to 3.1.2 or later.
Does an update remove malware that is already installed?
No. An update closes the entry point. Existing web shells, rogue administrators and database injections require a separate investigation and cleanup.
Why can a file scanner miss AntonKill?
In the Helix3 wave the injected code can live in template parameters in the database. A clean filesystem scan is therefore not proof that the site is clean.
Which ZOO version should I install?
Install ZOO 4.1.66 or later. It includes the critical 4.1.64 fixes and subsequent security updates.
Which YOOtheme Pro version contains the fixes?
The vendor lists both fixes in YOOtheme Pro 5.0.41. Review contributor and editor permissions after updating.
How the data is checked
Only confirmed CVEs, vendor guidance and public cybersecurity advisories are included. The review date is shown on this page, and the table is updated when recommendations change.
Already hacked or did the update not help?
Run the external check first. If there are redirects, spam, unknown administrators or earlier exposure, investigate files, the database and access logs.