Skip to content

Weekly roundup

Open-source business platforms, week 34 of 2026: Joomla and WordPress upload and access flaws lead 11 fixes

High 8.9 Vendor: Open-source business platforms 11 CVEs in scope Published

Open-source business platforms week 34 (17–23 August 2026) covers 11 CVEs: 10 Joomla! CMS and one WordPress. None are exploited or in CISA KEV. Four high-severity flaws include Joomla SHTML upload, WordPress PostScript RCE, ACL and MFA bypass. Patch Joomla to 5.4.8 or 6.1.3; update WordPress.

The release at a glance

Joomla! CMS published ten advisories on 18 August 2026, and WordPress published one on 17 August 2026. Across the week there are 11 CVEs in scope: four high severity and seven medium. Ten affect Joomla! CMS, one affects WordPress. None of the CVEs is listed in CISA KEV or reported as exploited. The main themes are file upload restrictions, access-control checks on webservice endpoints and authentication bypass. Both vendors have published fixes: Joomla! CMS 5.4.8 and 6.1.3, and WordPress 7.0.4 with backports to earlier branches from 4.7.

What matters most

WordPress: CVE-2026-65640 allows remote code execution through a malicious PostScript file uploaded by an Author-level or higher user. It requires Imagick and Ghostscript on the server and affects all versions before 7.0.4. The fix is in WordPress 7.0.4 and has been backported to branches from 4.7; the advisory is tracked as GHSA-8vr3-7mxf-gx8w and has its own advisory page on this site.

Joomla! CMS: CVE-2026-73373 is the highest-scored issue (8.9). The default dangerous-file list did not include SHTML, so an unrestricted SHTML upload could lead to code execution on servers that execute those files. It affects Joomla! CMS 1.0.0-5.4.6 and 6.0.0-6.1.2, and Joomla! Framework Filesystem package 1.0.0-3.3.0 and 4.0.0-4.2.0. CVE-2026-71574 (8.5) allows unauthorized mutation actions in webservice endpoints. CVE-2026-73337 (8.2) allows 2FA bypass through insufficient state checks. CVE-2026-71573 (6.9) covers improper CORS origin validation, and CVE-2026-72532 (5.1) allows creation of categories through webservice endpoints. The remaining Joomla flaws — CVE-2026-73371, CVE-2026-73372, CVE-2026-73336, CVE-2026-72531 and CVE-2026-71572 — are medium-severity access-control, XSS and response-header-injection issues. Joomla fixes are in 5.4.8 and 6.1.3.

Patch in this order

  1. Patch WordPress first. Move to 7.0.4 or the relevant backported branch for your series to close CVE-2026-65640. The requirement for Imagick and Ghostscript reduces exposure, but the result is remote code execution if those prerequisites are present.
  2. Patch Joomla! CMS upload paths. Apply 5.4.8 or 6.1.3 to close CVE-2026-73373, the SHTML upload issue; confirm whether your web server would execute SHTML when assessing urgency.
  3. Close the Joomla authentication and access-control gaps. The same Joomla update closes CVE-2026-73337 (MFA bypass), CVE-2026-71574 (mutating webservice endpoints), CVE-2026-71573 (CORS origin validation) and the medium-severity ACL/XSS/header-injection items.
  4. After patching, verify that externally reachable webservice endpoints and file upload endpoints are restricted. No CISA KEV due dates apply to this release.

Beyond the patch

Between the file upload and access-control issues, the main task is understanding which upload and webservice paths are actually reachable from your network. A penetration test and hardening review from Implementation & Assessment Services can establish that, while Virtual CISO Services can keep the resulting patch and exposure decisions on a repeat monthly cadence.

Every CVE in this release

CVEProductSeverity
CVE-2026-73373Joomla! CMSHigh 8.9Advisory →
CVE-2026-65640WordPressHigh 8.8Advisory →
CVE-2026-71574Joomla! CMSHigh 8.5Advisory →
CVE-2026-73337Joomla! CMSHigh 8.2Advisory →
CVE-2026-71573Joomla! CMSMedium 6.9Advisory →
CVE-2026-72532Joomla! CMSMedium 5.1Advisory →
CVE-2026-73371Joomla! CMSMedium 5.1Advisory →
CVE-2026-73372Joomla! CMSMedium 5.1Advisory →
CVE-2026-73336Joomla! CMSMedium 5.1Advisory →
CVE-2026-72531Joomla! CMSMedium 5.1Advisory →
CVE-2026-71572Joomla! CMSMedium 4.8

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.