Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells
Australia (ACSC) Warns of Global Campaign Exploiting (TL-2026-1224) is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-11. It has no confirmed attribution, affects eemitch Simple File List (WordPress plugin), references 7 CVEs (CVE-2025-34085, CVE-2020-36847, CVE-2026-0740), maps to 26 MITRE ATT&CK techniques (T1005, T1016, T1036), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1224
- Threat ID
- TL-2026-1224
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- small-to-medium business, web hosting, ecommerce, government administration, nonprofit, media publishing
- Target regions
- australia, Global
- Detection rules
- 9
- Indicators of compromise
- 23
The Australian Cyber Security Centre (ACSC) warns that malicious cyber actors are actively scanning websites and exploiting over 20 vulnerabilities across WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE to deploy webshells for persistent access. Multiple Australian small-to-medium businesses have already been compromised, with attackers using webshells to steal credentials and deploy additional malware.
How Australia (ACSC) Warns of Global Campaign Exploiting works
On 2026-07-11 the ACSC (part of the Australian Signals Directorate) published an alert describing a large-scale, ongoing exploitation campaign against publicly-facing website content management systems. Rather than relying on a single flaw, attackers are chaining more than 20 known CVEs across widely-deployed WordPress plugins (Simple File List, WavePlayer, BerqWP, WPBookit, Ninja Forms File Uploads, ThemeREX Addons, Breeze Cache, pay-uz, ACF Extended, Sneeit Framework, WPvivid Backup & Migration, Gravity Forms, GutenKit/Hunk Companion) and standalone CMS products (Craft CMS, MaxSite CMS, MetInfo CMS, Joomla JCE extension) to gain unauthenticated remote code execution and drop PHP webshells. Most of the WordPress-plugin CVEs are unrestricted/arbitrary file-upload flaws (CWE-434) allowing an attacker to upload a disguised or predictably-keyed PHP payload to a public directory and then execute it; Craft CMS's CVE-2025-32432 is a code-injection/PHP-object-deserialization gadget chain (CWE-94) and Joomla JCE's CVE-2026-48907 is a broken-access-control flaw (CWE-284) letting an unauthenticated user create an editor profile that can upload and execute PHP. Once a webshell is planted, operators use it for persistent access, credential theft (WordPress/CMS admin creds, hosting-panel creds), deployment of secondary malware, website defacement/disruption, delivery of malware to site visitors, and pivoting into the broader network. ACSC states many Australian SMBs have already been compromised and references a recent Five Eyes joint statement noting AI-assisted tooling is helping actors scale scanning and exploitation of newly disclosed CVEs faster than defenders can patch. This is the second such ACSC alert in two months, indicating the pattern of opportunistic mass-CVE-chaining against CMS platforms is continuing/escalating. Of the 7 CVEs tracked for this record: CVE-2025-34085 was rejected/withdrawn by its CNA as a duplicate of CVE-2020-36847 (Simple File List plugin RCE via file-rename, CVSS 9.8); CVE-2020-36847 (Simple File List, CVSS 9.8, CWE-434), CVE-2026-0740 (Ninja Forms File Uploads, CVSS 9.8, CWE-434), CVE-2026-3844 (Breeze Cache, CVSS 9.8, CWE-434), and CVE-2026-1357 (WPvivid Backup & Migration, CVSS 9.8, CWE-434) are all critical unauthenticated arbitrary-file-upload-to-RCE bugs; CVE-2025-32432 (Craft CMS, CVSS 10.0, CWE-94) is CISA KEV-listed (added 2026-03-20, remediation deadline 2026-04-03) and involves planting a malicious PHP session file then triggering a PhpManager gadget chain via an image-transform endpoint __class bypass; CVE-2026-48907 (Joomla JCE, CVSS 9.8/v3.1 and 10.0/v4.0, CWE-284) was added to CISA KEV on 2026-06-16 with confirmed active exploitation.
MITRE ATT&CK techniques used in TL-2026-1224
Collection
Discovery
T1016 System Network Configuration Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Persistence
T1078 Valid Accounts; T1136 Create Account; T1505 Server Software Component
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1489 Service Stop; T1491 Defacement
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Exfiltration
T1567 Exfiltration Over Web Service
Lateral Movement
Resource Development
T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in Australia (ACSC) Warns of Global Campaign Exploiting
- eemitch — Simple File List (WordPress plugin)
- SaturdayDrive — Ninja Forms - File Uploads (WordPress add-on)
- Cloudways — Breeze Cache (WordPress plugin)
- wpvividplugins — WPvivid - Backup, Migration & Staging (WordPress plugin)
- Pixel & Tonic — Craft CMS
- Widget Factory Limited — JCE (Joomla Content Editor extension)
- Unknown — MaxSite CMS
- Unknown — MetInfo CMS
- Unknown — WordPress core plugins (broader campaign, non-tracked CVEs)
Remediation for Australia (ACSC) Warns of Global Campaign Exploiting
Patches
- Simple File List 4.2.3
- Ninja Forms - File Uploads 3.3.27
- Craft CMS 3.9.15 / 4.14.15 / 5.6.17
- Joomla JCE 2.9.99.5
Immediate actions
- Patch/upgrade Simple File List plugin to 4.2.3+ (fixes CVE-2020-36847 / duplicate CVE-2025-34085)
- Patch/upgrade Ninja Forms - File Uploads add-on to 3.3.27+ (CVE-2026-0740)
- Patch/upgrade Breeze Cache plugin to a version beyond 2.4.4, or disable 'Host Files Locally - Gravatars' feature (CVE-2026-3844)
- Patch/upgrade WPvivid Backup & Migration plugin beyond 0.9.123 (CVE-2026-1357)
- Patch Craft CMS to 3.9.15 / 4.14.15 / 5.6.17 or later immediately — actively exploited, CISA KEV mandated deadline already passed (CVE-2025-32432)
- Patch Joomla JCE extension to 2.9.99.5+ immediately — actively exploited, CISA KEV listed (CVE-2026-48907)
- Scan all public-facing WordPress/Joomla/Craft/MaxSite/MetInfo installations for unauthorized PHP files, unexpected admin/editor accounts, and modified core/plugin files
- Rotate all CMS admin, hosting panel, database, and API credentials on any potentially-affected site
Workarounds
- Disable 'Host Files Locally - Gravatars' feature in Breeze Cache if patch cannot be applied immediately
- Disable/remove vulnerable plugins entirely if a patch is not yet available
- Restrict file-upload endpoints via WAF rules pending patch deployment
Longer-term hardening
- Adopt a CMS/plugin inventory and automated patch-management process for third-party WordPress plugins and CMS extensions
- Deploy a web application firewall (WAF) in front of CMS installations to block known exploit patterns for file-upload and deserialization flaws
- Implement file-integrity monitoring on webroot directories to detect webshell drops
- Restrict plugin/extension installation privileges and disable unused plugins/features
- Segment web-hosting infrastructure from internal networks to limit lateral-movement impact of a compromised website
CVEs associated with Australia (ACSC) Warns of Global Campaign Exploiting
CVE-2025-34085, CVE-2020-36847, CVE-2026-0740, CVE-2026-3844, CVE-2026-1357, CVE-2025-32432, CVE-2026-48907
Weaknesses (CWE) in Australia (ACSC) Warns of Global Campaign Exploiting
CWE-434, CWE-94, CWE-284
Timeline of Australia (ACSC) Warns of Global Campaign Exploiting
- CVE-2020-36847 (Simple File List WordPress plugin, unrestricted PHP file upload via rename function) originally disclosed/tracked.
- CVE-2025-32432 (Craft CMS unauthenticated RCE via session-file poisoning and PhpManager gadget chain) published, CVSS 10.0.
- CVE-2025-34085 published then subsequently rejected/withdrawn by its CNA as a duplicate of CVE-2020-36847.
- CVE-2020-36847 NVD record updated/republished with CVSS 9.8 (Simple File List RCE).
- CVE-2026-1357 (WPvivid Backup & Migration unauthenticated arbitrary file upload / RCE) published, CVSS 9.8.
- CISA adds CVE-2025-32432 (Craft CMS) to the Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-04-03.
- CVE-2026-0740 (Ninja Forms File Uploads add-on unauthenticated arbitrary file upload) published, CVSS 9.8.
- CVE-2026-3844 (Breeze Cache plugin unauthenticated arbitrary file upload via fetch_gravatar_from_remote) published, CVSS 9.8.
- CVE-2026-48907 (Joomla JCE extension broken access control enabling unauthorized editor profile creation and PHP upload) published.
- CISA adds CVE-2026-48907 (Joomla JCE) to the Known Exploited Vulnerabilities catalog with confirmed active exploitation.
- TL-Intel-Harness HUNT phase ingests the BleepingComputer article and generates threat skeleton TL-2026-1224.
- BleepingComputer publishes coverage of the ACSC advisory, listing the full set of exploited CVEs and noting the campaign may be AI-assisted per a recent Five Eyes joint statement.
- ACSC publishes advisory 'Large-scale exploitation campaign targeting website content management systems (CMS)', warning of chained exploitation of 20+ CVEs across WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE, with confirmed compromise of multiple Australian SMBs.
Sources cited for Australia (ACSC) Warns of Global Campaign Exploiting
- Australia warns of global campaign targeting vulnerable CMS platforms
- Large-scale exploitation campaign targeting website content management systems (CMS)
- ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites
- ACSC warns of large-scale campaign exploiting CMS vulnerabilities in Australia
- Critical alert! ACSC warns of 'large-scale exploitation' of Aussie websites
- Second alert from ACSC in two months shows unpatched CMS bugs still exploited
- CVE-2020-36847 Detail - NVD
- CVE-2025-34085 Detail - NVD (rejected/duplicate)
- CVE-2026-0740 Detail - NVD
- CVE-2026-3844 Detail - NVD
- CVE-2026-1357 Detail - NVD
- CVE-2025-32432 Detail - NVD
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
- CVE-2025-32432: Craft CMS RCE Vulnerability Explained
- Critical vulnerability in WPvivid backup plugin allows remote code execution
Threats related to Australia (ACSC) Warns of Global Campaign Exploiting
- Zero-Day Exploitation of Joomla iCagenda and Balbooa Forms Extensions via Unauthenticated Arbitrary File Upload (CVE-2026-48939, CVE-2026-56291)
- WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage Targeting 1.4M Domains via CVE-2026-48907 (Joomla JCE) and CVE-2021-29441 (Nacos)
- CVE-2026-48907 — JCE (Joomla Content Editor) Improper Access Control Enabling Unauthenticated PHP Code Upload and Remote Code Execution
- ShapedPlugin WordPress Pro Plugins Backdoored via Build-Pipeline Supply Chain Compromise (CVE-2026-49777, CVE-2026-10735)
Detection coverage for TL-2026-1224
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1224 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.