Multiple vulnerabilities in Joomla! (August 19, 2026)
Multiple vulnerabilities have been discovered in Joomla!. Some of them allow an attacker to cause remote arbitrary code execution, data integrity breach and remote indirect code injection (XSS).
CSIRTS triage
- What
- Multiple vulnerabilities enable remote arbitrary code execution, data integrity breach, and remote indirect code injection via XSS.
- Who is affected
- Joomla deployments running affected versions.
- Urgency
- Critical; remote arbitrary code execution vulnerabilities require immediate patching to prevent system compromise.
- Action
- Update Joomla to the latest patched version addressing all listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Joomla
Get an email when a new Joomla advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1046/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-733710.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733370.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733360.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-715740.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-715720.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-725320.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733730.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-725310.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-715730.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733720.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-73371 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73336 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71574 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71572 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-72532 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73373 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-72531 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71573 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73372 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Joomla: Multiple vulnerabilitiescert-bund
- unknownCVE-2026-73372: Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joom…nvd
- unknownCVE-2026-73336: Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 …nvd
- unknownCVE-2026-72531: Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joom…nvd
- unknownCVE-2026-71573: Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2…nvd
- unknownCVE-2026-71572: Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7,…nvd
- unknownCVE-2026-73373: Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6…nvd
- unknownCVE-2026-73371: Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, …nvd
- unknownCVE-2026-73337: Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - …nvd
- unknownCVE-2026-72532: Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.…nvd
- unknownCVE-2026-71574: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Jooml…nvd
Recent advisories for Joomla!
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-75956: Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDi…nvd · 2026-08-19
- unknownCVE-2026-75955: Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.…nvd · 2026-08-19
- unknownCVE-2026-75954: Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.…nvd · 2026-08-19
- unknownCVE-2026-75953: Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient …nvd · 2026-08-19
- unknownCVE-2026-75952: Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 -…nvd · 2026-08-19
- unknownCVE-2026-75951: Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API act…nvd · 2026-08-19
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Oracle Virtualization (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Axis products (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)2026-08-19