Alex Yao Alex Yao
Back to news
Cyber Security Published on July 9, 2026

ACSC warns of large-scale global CMS exploitation campaign

The Australian Cyber Security Centre issued a critical alert about a large-scale campaign exploiting known vulnerabilities in content management systems.

Affected platforms include WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE.

Attackers deploy webshells to gain persistent remote access to compromised servers.

All listed vulnerabilities have patches available; ACSC urges immediate patching and system audits.