Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells

Australia (ACSC) Warns of Global Campaign Exploiting (TL-2026-1224) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-11. It has no confirmed attribution, affects eemitch Simple File List (WordPress plugin), references 7 CVEs (CVE-2025-34085, CVE-2020-36847, CVE-2026-0740), maps to 26 MITRE ATT&CK techniques (T1005, T1016, T1036), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-1224

Threat ID
TL-2026-1224
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-11
Last reviewed
2026-07-11
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
small-to-medium business, web hosting, ecommerce, government administration, nonprofit, media publishing
Target regions
australia, Global
Detection rules
9
Indicators of compromise
23

The Australian Cyber Security Centre (ACSC) warns that malicious cyber actors are actively scanning websites and exploiting over 20 vulnerabilities across WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE to deploy webshells for persistent access. Multiple Australian small-to-medium businesses have already been compromised, with attackers using webshells to steal credentials and deploy additional malware.

How Australia (ACSC) Warns of Global Campaign Exploiting works

On 2026-07-11 the ACSC (part of the Australian Signals Directorate) published an alert describing a large-scale, ongoing exploitation campaign against publicly-facing website content management systems. Rather than relying on a single flaw, attackers are chaining more than 20 known CVEs across widely-deployed WordPress plugins (Simple File List, WavePlayer, BerqWP, WPBookit, Ninja Forms File Uploads, ThemeREX Addons, Breeze Cache, pay-uz, ACF Extended, Sneeit Framework, WPvivid Backup & Migration, Gravity Forms, GutenKit/Hunk Companion) and standalone CMS products (Craft CMS, MaxSite CMS, MetInfo CMS, Joomla JCE extension) to gain unauthenticated remote code execution and drop PHP webshells. Most of the WordPress-plugin CVEs are unrestricted/arbitrary file-upload flaws (CWE-434) allowing an attacker to upload a disguised or predictably-keyed PHP payload to a public directory and then execute it; Craft CMS's CVE-2025-32432 is a code-injection/PHP-object-deserialization gadget chain (CWE-94) and Joomla JCE's CVE-2026-48907 is a broken-access-control flaw (CWE-284) letting an unauthenticated user create an editor profile that can upload and execute PHP. Once a webshell is planted, operators use it for persistent access, credential theft (WordPress/CMS admin creds, hosting-panel creds), deployment of secondary malware, website defacement/disruption, delivery of malware to site visitors, and pivoting into the broader network. ACSC states many Australian SMBs have already been compromised and references a recent Five Eyes joint statement noting AI-assisted tooling is helping actors scale scanning and exploitation of newly disclosed CVEs faster than defenders can patch. This is the second such ACSC alert in two months, indicating the pattern of opportunistic mass-CVE-chaining against CMS platforms is continuing/escalating. Of the 7 CVEs tracked for this record: CVE-2025-34085 was rejected/withdrawn by its CNA as a duplicate of CVE-2020-36847 (Simple File List plugin RCE via file-rename, CVSS 9.8); CVE-2020-36847 (Simple File List, CVSS 9.8, CWE-434), CVE-2026-0740 (Ninja Forms File Uploads, CVSS 9.8, CWE-434), CVE-2026-3844 (Breeze Cache, CVSS 9.8, CWE-434), and CVE-2026-1357 (WPvivid Backup & Migration, CVSS 9.8, CWE-434) are all critical unauthenticated arbitrary-file-upload-to-RCE bugs; CVE-2025-32432 (Craft CMS, CVSS 10.0, CWE-94) is CISA KEV-listed (added 2026-03-20, remediation deadline 2026-04-03) and involves planting a malicious PHP session file then triggering a PhpManager gadget chain via an image-transform endpoint __class bypass; CVE-2026-48907 (Joomla JCE, CVSS 9.8/v3.1 and 10.0/v4.0, CWE-284) was added to CISA KEV on 2026-06-16 with confirmed active exploitation.

MITRE ATT&CK techniques used in TL-2026-1224

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

Persistence

T1078 Valid Accounts; T1136 Create Account; T1505 Server Software Component

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1489 Service Stop; T1491 Defacement

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Exfiltration

T1567 Exfiltration Over Web Service

Lateral Movement

T1570 Lateral Tool Transfer

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1593 Search Open Websites/Domains; T1595 Active Scanning

Affected products and versions in Australia (ACSC) Warns of Global Campaign Exploiting

  • eemitch — Simple File List (WordPress plugin)
  • SaturdayDrive — Ninja Forms - File Uploads (WordPress add-on)
  • Cloudways — Breeze Cache (WordPress plugin)
  • wpvividplugins — WPvivid - Backup, Migration & Staging (WordPress plugin)
  • Pixel & Tonic — Craft CMS
  • Widget Factory Limited — JCE (Joomla Content Editor extension)
  • Unknown — MaxSite CMS
  • Unknown — MetInfo CMS
  • Unknown — WordPress core plugins (broader campaign, non-tracked CVEs)

Remediation for Australia (ACSC) Warns of Global Campaign Exploiting

Patches

  • Simple File List 4.2.3
  • Ninja Forms - File Uploads 3.3.27
  • Craft CMS 3.9.15 / 4.14.15 / 5.6.17
  • Joomla JCE 2.9.99.5

Immediate actions

  • Patch/upgrade Simple File List plugin to 4.2.3+ (fixes CVE-2020-36847 / duplicate CVE-2025-34085)
  • Patch/upgrade Ninja Forms - File Uploads add-on to 3.3.27+ (CVE-2026-0740)
  • Patch/upgrade Breeze Cache plugin to a version beyond 2.4.4, or disable 'Host Files Locally - Gravatars' feature (CVE-2026-3844)
  • Patch/upgrade WPvivid Backup & Migration plugin beyond 0.9.123 (CVE-2026-1357)
  • Patch Craft CMS to 3.9.15 / 4.14.15 / 5.6.17 or later immediately — actively exploited, CISA KEV mandated deadline already passed (CVE-2025-32432)
  • Patch Joomla JCE extension to 2.9.99.5+ immediately — actively exploited, CISA KEV listed (CVE-2026-48907)
  • Scan all public-facing WordPress/Joomla/Craft/MaxSite/MetInfo installations for unauthorized PHP files, unexpected admin/editor accounts, and modified core/plugin files
  • Rotate all CMS admin, hosting panel, database, and API credentials on any potentially-affected site

Workarounds

  • Disable 'Host Files Locally - Gravatars' feature in Breeze Cache if patch cannot be applied immediately
  • Disable/remove vulnerable plugins entirely if a patch is not yet available
  • Restrict file-upload endpoints via WAF rules pending patch deployment

Longer-term hardening

  • Adopt a CMS/plugin inventory and automated patch-management process for third-party WordPress plugins and CMS extensions
  • Deploy a web application firewall (WAF) in front of CMS installations to block known exploit patterns for file-upload and deserialization flaws
  • Implement file-integrity monitoring on webroot directories to detect webshell drops
  • Restrict plugin/extension installation privileges and disable unused plugins/features
  • Segment web-hosting infrastructure from internal networks to limit lateral-movement impact of a compromised website

CVEs associated with Australia (ACSC) Warns of Global Campaign Exploiting

CVE-2025-34085, CVE-2020-36847, CVE-2026-0740, CVE-2026-3844, CVE-2026-1357, CVE-2025-32432, CVE-2026-48907

Weaknesses (CWE) in Australia (ACSC) Warns of Global Campaign Exploiting

CWE-434, CWE-94, CWE-284

Timeline of Australia (ACSC) Warns of Global Campaign Exploiting

  • CVE-2020-36847 (Simple File List WordPress plugin, unrestricted PHP file upload via rename function) originally disclosed/tracked.
  • CVE-2025-32432 (Craft CMS unauthenticated RCE via session-file poisoning and PhpManager gadget chain) published, CVSS 10.0.
  • CVE-2025-34085 published then subsequently rejected/withdrawn by its CNA as a duplicate of CVE-2020-36847.
  • CVE-2020-36847 NVD record updated/republished with CVSS 9.8 (Simple File List RCE).
  • CVE-2026-1357 (WPvivid Backup & Migration unauthenticated arbitrary file upload / RCE) published, CVSS 9.8.
  • CISA adds CVE-2025-32432 (Craft CMS) to the Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-04-03.
  • CVE-2026-0740 (Ninja Forms File Uploads add-on unauthenticated arbitrary file upload) published, CVSS 9.8.
  • CVE-2026-3844 (Breeze Cache plugin unauthenticated arbitrary file upload via fetch_gravatar_from_remote) published, CVSS 9.8.
  • CVE-2026-48907 (Joomla JCE extension broken access control enabling unauthorized editor profile creation and PHP upload) published.
  • CISA adds CVE-2026-48907 (Joomla JCE) to the Known Exploited Vulnerabilities catalog with confirmed active exploitation.
  • TL-Intel-Harness HUNT phase ingests the BleepingComputer article and generates threat skeleton TL-2026-1224.
  • BleepingComputer publishes coverage of the ACSC advisory, listing the full set of exploited CVEs and noting the campaign may be AI-assisted per a recent Five Eyes joint statement.
  • ACSC publishes advisory 'Large-scale exploitation campaign targeting website content management systems (CMS)', warning of chained exploitation of 20+ CVEs across WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE, with confirmed compromise of multiple Australian SMBs.

Sources cited for Australia (ACSC) Warns of Global Campaign Exploiting

Threats related to Australia (ACSC) Warns of Global Campaign Exploiting

Detection coverage for TL-2026-1224

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1224 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats