INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms
| 2026-07-13 07:39 VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On July 13, 2026, Australia's Signals Directorate issued an alert about a large-scale exploitation campaign targeting content management systems (CMS) worldwide, with many small and medium-sized Australian businesses already hit. The attackers are scanning websites for known vulnerabilities, deploying webshells to gain persistent remote access, and using compromised servers as a base for broader attacks. The targeted software includes 17 CVEs across WordPress plugins and standalone CMS platforms such as Craft CMS, Joomla, and MaxSite CMS. All of the vulnerabilities are public and patched, but attackers are exploiting them on websites that have not been updated. Once deployed, webshells can allow malicious cyber actors to remotely access and control targeted web servers for various purposes including website defacement or disruption, capturing credentials, uploading additional malware, and using web server access as a pathway for broader network compromise.
Technical Mitigations AI-generated
• Review access logs for GET or POST requests to unusual paths on Craft CMS (CVE-2025-32432)
• Check web directories for unexpected files, especially in plugin folders, and review access logs for signs of lateral movement or additional accounts created on MaxSite CMS (CVE-2026-3395)
• Use a technique to detect webshells such as looking for suspicious file uploads or unusual network activity on Joomla JCE (CVE-2026-48907)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Intelligence Sources
BleepingComputer
2026-07-11
Security Affairs
2026-07-13
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Security Affairs