CiberLATAMbywhalemate

Brazil and Costa Rica Warn on Joomla JCE

CTIR Gov and Costa Rica’s CSIRT are coordinating alerts over an active campaign targeting Joomla sites with outdated JCE.

Whalemate Labs · AI-assisted researchJul 16, 20262 min read

Brazil’s CTIR Gov issued ALERTA 56/2026 on a campaign targeting Joomla installations using the Joomla Content Editor (JCE) component without the latest fixes from the developer, and tied its response to earlier alerts from Costa Rica’s CSIRT. In parallel, Spain’s INCIBE warned about two vulnerabilities in SonicWall SMA1000, including one critical flaw already patched by the vendor.

Active campaign targets Joomla with vulnerable JCE

Brazil’s Institutional Security Office, through CTIR Gov, issued ALERTA 56/2026 on a compromise campaign affecting Joomla installations that use the Joomla Content Editor (JCE) component when it is outdated or missing the developer’s latest fixes. The notice asks institutions to identify whether they are running vulnerable versions and immediately apply the fixes needed to keep both Joomla and JCE up to date.

According to CTIR Gov, vulnerable versions include JCE installations that are outdated or do not have the latest patches. The official guidance also calls for adding the campaign’s indicators of compromise to EDR, SIEM, IDS/IPS, WAF and monitoring platforms right away, and for conducting retrospective hunts for the hashes and file names identified in logs and security systems.

Detection and tracking measures

The alert also advises checking for unauthorized PHP files in upload, cache, image and temporary directories on Joomla servers that may have been compromised. It also instructs teams to review web access logs to identify historical connections linked to addresses and endpoints associated with the campaign.

CTIR Gov also asked organizations to keep applying the mitigation measures established in Costa Rica’s alerts MICITT-DC-CSIRT-SOC-AT-000799-2026 and MICITT-DC-CSIRT-SOC-AT-000804-2026. The explicit reference to those notices shows coordination between Latin American national CSIRTs in response to malicious activity targeting Joomla and JCE.

INCIBE warns on SonicWall SMA1000

In parallel, Spain’s National Cybersecurity Institute, INCIBE, published an advisory on two vulnerabilities in SonicWall SMA1000 devices. One is critical, CVE-2026-15409, and involves an SSRF flaw in the Workplace interface. The other, CVE-2026-15410, is high severity and stems from improper code generation control in the AMC administration console.

According to the advisory, CVE-2026-15409 could allow an unauthenticated attacker to make unauthorized requests or execute commands as an administrator. In the case of CVE-2026-15410, an attacker authenticated as an administrator could execute arbitrary commands on the device’s operating system.

Affected versions include 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800. SonicWall has already released updates to fix both issues, with 12.4.3-03453 and later in the 12.4.3 branch, and 12.5.0-02835 and later in the 12.5.0 branch.

INCIBE recommended applying the updates immediately, especially in environments where administrative interfaces are exposed to the internet. SonicWall said that, as of the advisory date cited by INCIBE, it had not detected active exploitation of these flaws, although its PSIRT emphasized that patching should not be delayed.

Sources

View all