The Bottom Line: Cybercriminals are conducting a global campaign exploiting vulnerabilities in WordPress, Joomla and other CMS systems to deploy webshells and gain administrator access.
Australia’s cybersecurity centre ACSC is warning of a worldwide attack wave in which cybercriminals are systematically exploiting vulnerabilities in popular content management systems to install webshells and gain administrative access.
The ACSC reports a coordinated campaign in which malicious actors systematically scan websites for exploitation opportunities. The attackers exploit various vulnerability classes: unauthenticated file uploads, remote code execution, server-side request forgery (SSRF) and deserialization flaws in CMS software and their plugins. In addition to market leaders WordPress and Joomla (specifically the Joomla Content Editor plugin), Craft CMS, MaxSite CMS, MetInfo CMS and the Sneeit Framework are also affected.
Following successful webshell installation, the attackers gain full administrative remote access to the web server. This enables them to manipulate web content, steal customer data, distribute malware and move laterally into internal corporate networks. In Australia, numerous SMEs have already reported compromises of their web presence. The ACSC explicitly emphasises the global reach of this campaign.
To counter the threat, the authority recommends: continuous monitoring of network and access logs for anomalies, review of all user accounts for unauthorised new creations, immediate installation of all available security updates for CMS and plugins, restriction of file creation rights on the server, and strict network segmentation. If a successful compromise is suspected, a clean backup created before the incident should be deployed.
The ACSC also warns of shortened response times: the time between the disclosure of new security vulnerabilities and their active exploitation by attackers is becoming increasingly shorter, in some cases accelerated by the use of AI automation in attack operations.
Source: www.it-daily.net · Published 13 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.