Weekly roundup
Open-source business platforms, week 34 of 2026: Joomla and WordPress upload and access flaws lead 11 fixes
Open-source business platforms week 34 (17–23 August 2026) covers 11 CVEs: 10 Joomla! CMS and one WordPress. None are exploited or in CISA KEV. Four high-severity flaws include Joomla SHTML upload, WordPress PostScript RCE, ACL and MFA bypass. Patch Joomla to 5.4.8 or 6.1.3; update WordPress.
The release at a glance
Joomla! CMS published ten advisories on 18 August 2026, and WordPress published one on 17 August 2026. Across the week there are 11 CVEs in scope: four high severity and seven medium. Ten affect Joomla! CMS, one affects WordPress. None of the CVEs is listed in CISA KEV or reported as exploited. The main themes are file upload restrictions, access-control checks on webservice endpoints and authentication bypass. Both vendors have published fixes: Joomla! CMS 5.4.8 and 6.1.3, and WordPress 7.0.4 with backports to earlier branches from 4.7.
What matters most
WordPress: CVE-2026-65640 allows remote code execution through a malicious PostScript file uploaded by an Author-level or higher user. It requires Imagick and Ghostscript on the server and affects all versions before 7.0.4. The fix is in WordPress 7.0.4 and has been backported to branches from 4.7; the advisory is tracked as GHSA-8vr3-7mxf-gx8w and has its own advisory page on this site.
Joomla! CMS: CVE-2026-73373 is the highest-scored issue (8.9). The default dangerous-file list did not include SHTML, so an unrestricted SHTML upload could lead to code execution on servers that execute those files. It affects Joomla! CMS 1.0.0-5.4.6 and 6.0.0-6.1.2, and Joomla! Framework Filesystem package 1.0.0-3.3.0 and 4.0.0-4.2.0. CVE-2026-71574 (8.5) allows unauthorized mutation actions in webservice endpoints. CVE-2026-73337 (8.2) allows 2FA bypass through insufficient state checks. CVE-2026-71573 (6.9) covers improper CORS origin validation, and CVE-2026-72532 (5.1) allows creation of categories through webservice endpoints. The remaining Joomla flaws — CVE-2026-73371, CVE-2026-73372, CVE-2026-73336, CVE-2026-72531 and CVE-2026-71572 — are medium-severity access-control, XSS and response-header-injection issues. Joomla fixes are in 5.4.8 and 6.1.3.
Patch in this order
- Patch WordPress first. Move to 7.0.4 or the relevant backported branch for your series to close CVE-2026-65640. The requirement for Imagick and Ghostscript reduces exposure, but the result is remote code execution if those prerequisites are present.
- Patch Joomla! CMS upload paths. Apply 5.4.8 or 6.1.3 to close CVE-2026-73373, the SHTML upload issue; confirm whether your web server would execute SHTML when assessing urgency.
- Close the Joomla authentication and access-control gaps. The same Joomla update closes CVE-2026-73337 (MFA bypass), CVE-2026-71574 (mutating webservice endpoints), CVE-2026-71573 (CORS origin validation) and the medium-severity ACL/XSS/header-injection items.
- After patching, verify that externally reachable webservice endpoints and file upload endpoints are restricted. No CISA KEV due dates apply to this release.
Beyond the patch
Between the file upload and access-control issues, the main task is understanding which upload and webservice paths are actually reachable from your network. A penetration test and hardening review from Implementation & Assessment Services can establish that, while Virtual CISO Services can keep the resulting patch and exposure decisions on a repeat monthly cadence.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-73373 | Joomla! CMS | High 8.9 | Advisory → |
| CVE-2026-65640 | WordPress | High 8.8 | Advisory → |
| CVE-2026-71574 | Joomla! CMS | High 8.5 | Advisory → |
| CVE-2026-73337 | Joomla! CMS | High 8.2 | Advisory → |
| CVE-2026-71573 | Joomla! CMS | Medium 6.9 | Advisory → |
| CVE-2026-72532 | Joomla! CMS | Medium 5.1 | Advisory → |
| CVE-2026-73371 | Joomla! CMS | Medium 5.1 | Advisory → |
| CVE-2026-73372 | Joomla! CMS | Medium 5.1 | Advisory → |
| CVE-2026-73336 | Joomla! CMS | Medium 5.1 | Advisory → |
| CVE-2026-72531 | Joomla! CMS | Medium 5.1 | Advisory → |
| CVE-2026-71572 | Joomla! CMS | Medium 4.8 |
References
Vendor advisory
- Joomla! security announcement [20260810]: Unrestricted uploads of SHTML files
- Remote code execution vulnerability via malicious file upload by an Author level user o…
- Joomla! security announcement [20260803]: Inconsistent ACL checks for mutating webservi…
- Joomla! security announcement [20260807]: MFA Authentication Bypass
- developer.joomla.org/security-centre/20260802-core-improper-cors-origin-validation.html
- Joomla! security announcement [20260802]: Improper CORS origin validation
- Joomla! security announcement [20260805]: Improper ACL checks for category webservice e…
- Joomla! security announcement [20260808]: Improper ACL checks for batch copy actions
CVE
- CVE-2026-73373 — cve.org
- CVE-2026-73373 — NVD
- CVE-2026-65640 — cve.org
- CVE-2026-65640 — NVD
- CVE-2026-71574 — cve.org
- CVE-2026-71574 — NVD
- CVE-2026-73337 — cve.org
- CVE-2026-73337 — NVD
- CVE-2026-71573 — cve.org
- CVE-2026-71573 — NVD
- CVE-2026-72532 — cve.org
- CVE-2026-72532 — NVD
- CVE-2026-73371 — cve.org
- CVE-2026-73371 — NVD
- CVE-2026-73372 — cve.org
- CVE-2026-73372 — NVD
- CVE-2026-73336 — cve.org
- CVE-2026-73336 — NVD
- CVE-2026-72531 — cve.org
- CVE-2026-72531 — NVD
- CVE-2026-71572 — cve.org
- CVE-2026-71572 — NVD