Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells — Threadlinqs Intelligence
As of 2026-07-11, Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1224 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
The Australian Cyber Security Centre (ACSC) warns that malicious cyber actors are actively scanning websites and exploiting over 20 vulnerabilities across WordPress plugins, Craft CMS, MaxSite CMS,
On 2026-07-11 the ACSC (part of the Australian Signals Directorate) published an alert describing a large-scale, ongoing exploitation campaign against publicly-facing website content management systems. Rather than relying on a single flaw, attackers are chaining more than 20 known CVEs across widely-deployed WordPress plugins (Simple File List, WavePlayer, BerqWP, WPBookit, Ninja Forms File Uploads, ThemeREX Addons, Breeze Cache, pay-uz, ACF Extended, Sneeit Framework, WPvivid Backup & Migration, Gravity Forms, GutenKit/Hunk Companion) and standalone CMS products (Craft CMS, MaxSite CMS, MetInfo CMS, Joomla JCE extension) to gain unauthenticated remote code execution and drop PHP webshells. Most of the WordPress-plugin CVEs are unrestricted/arbitrary file-upload flaws (CWE-434) allowing an attacker to upload a disguised or predictably-keyed PHP payload to a public directory and then execute it; Craft CMS's CVE-2025-32432 is a code-injection/PHP-object-deserialization gadget chain (CWE-94) and Joomla JCE's CVE-2026-48907 is a broken-access-control flaw (CWE-284) letting an unauthenticated user create an editor profile that can upload and execute PHP. Once a webshell is planted, operators use it for persistent access, credential theft (WordPress/CMS admin creds, hosting-panel creds), deployment of secondary malware, website defacement/disruption, delivery of malware to site visitors, and pivoting into the broader network. ACSC states many Australian SMBs have already been compromised and references a recent Five Eyes joint statement noting AI-assisted tooling is helping actors scale scanning and exploitation of newly disclosed CVEs faster than defenders can patch. This is the second such ACSC alert in two months, indicating the pattern of opportunistic mass-CVE-chaining against CMS platforms is continuing/escalating. Of the 7 CVEs tracked for this record: CVE-2025-34085 was rejected/withdrawn by its CNA as a duplicate of CVE-2020-36847 (Simple File List plugin RCE via file-rename, CVSS 9.8); CVE-2020-36847 (Simple File List, CVSS 9.8, CWE-434), CVE-2026-0740 (Ninja Forms File Uploads, CVSS 9.8, CWE-434), CVE-2026-3844 (Breeze Cache, CVSS 9.8, CWE-434), and CVE-2026-1357 (WPvivid Backup & Migration, CVSS 9.8, CWE-434) are all critical unauthenticated arbitrary-file-upload-to-RCE bugs; CVE-2025-32432 (Craft CMS, CVSS 10.0, CWE-94) is CISA KEV-listed (added 2026-03-20, remediation deadline 2026-04-03) and involves planting a malicious PHP session file then triggering a PhpManager gadget chain via an image-transform endpoint __class bypass; CVE-2026-48907 (Joomla JCE, CVSS 9.8/v3.1 and 10.0/v4.0, CWE-284) was added to CISA KEV on 2026-06-16 with confirmed active exploitation.
Weaknesses (CWE)
CWE-434, CWE-94, CWE-284
Target sectors: small-to-medium business, web hosting, ecommerce, government administration, nonprofit, media publishing
Target regions: australia, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-34085, CVE-2020-36847, CVE-2026-0740, CVE-2026-3844, CVE-2026-1357, CVE-2025-32432, CVE-2026-48907, T1595, T1593, T1587, T1588, T1190, T1059, T1203, T1505, T1136, T1078