Current Joomla vulnerabilities and the versions to update

A concise technical list for Joomla owners and administrators, based on confirmed affected versions, fixes and primary-source data. An update closes the known entry point but does not remove an existing backdoor.

13 CVEsconfirmed
Highupdate priority
23.08.2026last reviewed

Verified vulnerabilities

Compare the installed version and close the known entry point first.

ComponentAffectedActionStatusVerification
JCE
CVE-2026-48907
up to 2.9.99.4Update to 2.9.99.9 or newerActively exploitedVerified
SP Page Builder
CVE-2026-48908
up to 6.6.1Update to 6.6.2 or newerActively exploitedVerified
Helix3
CVE-2026-49049
up to 3.1.1Update both plugins to 3.1.2 or newerMass attacks reportedVerified
ZOO
CVE-2026-74803
CVE-2026-74804
CVE-2026-75114
CVE-2026-76610
CVE-2026-76611
CVE-2026-76612
CVE-2026-77028
CVE-2026-77029
1.0.0-4.1.63 for 74803/74804; additional fixes followedUpdate to 4.1.66 or newerCritical patchVendor changelog
YOOtheme Pro
CVE-2026-75115
CVE-2026-76613
vendor lists the fixes in version 5.0.41Update to 5.0.41 or newerSecurity patchVendor changelog

21 August YOOtheme security updates

Install the latest vendor packages even if Joomla does not yet show an update notification.

ZOO 4.1.66 includes the earlier fixes for unauthenticated arbitrary file upload (CVE-2026-74803) and unauthenticated SQL injection (CVE-2026-74804), plus additional path traversal, XSS, redirect and CSRF fixes. Use the ZOO vendor changelog as the version source.

Detailed ZOO 4.1.66 response guide: CVE-2026-74803 and CVE-2026-74804.

YOOtheme Pro 5.0.41 fixes an arbitrary file-read issue and SQL injection available to contributor-level users. Verify the installed version after updating and review accounts with content-editing access. See the YOOtheme Pro vendor changelog.

Detailed YOOtheme Pro 5.0.41 response guide: CVE-2026-75115 and CVE-2026-76613.

If ZOO frontend submissions were exposed before patching, preserve logs before cleanup and inspect uploaded files, unexpected administrator accounts, modified PHP or JavaScript and scheduled tasks. Updating closes the documented code paths; it does not prove that an internet-facing site was not reached earlier.

What to do first

  1. Preserve a copy of the files, database and access logs before cleanup.
  2. Isolate the site or place it in a safe maintenance mode.
  3. Update the vulnerable component, then inspect files, database records, users and persistence points.
  4. Rotate access credentials and recheck the site after 24 hours and 7 days.

Direct answers

Is Helix3 3.1.1 safe?

NVD lists versions through 3.1.1 as affected. Update both Helix3 plugins to 3.1.2 or later.

Does an update remove malware that is already installed?

No. An update closes the entry point. Existing web shells, rogue administrators and database injections require a separate investigation and cleanup.

Why can a file scanner miss AntonKill?

In the Helix3 wave the injected code can live in template parameters in the database. A clean filesystem scan is therefore not proof that the site is clean.

Which ZOO version should I install?

Install ZOO 4.1.66 or later. It includes the critical 4.1.64 fixes and subsequent security updates.

Which YOOtheme Pro version contains the fixes?

The vendor lists both fixes in YOOtheme Pro 5.0.41. Review contributor and editor permissions after updating.

How the data is checked

Only confirmed CVEs, vendor guidance and public cybersecurity advisories are included. The review date is shown on this page, and the table is updated when recommendations change.

NVD CVE databaseVendor guidanceCERT advisories

Already hacked or did the update not help?

Run the external check first. If there are redirects, spam, unknown administrators or earlier exposure, investigate files, the database and access logs.