News - Security News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
A critical Fabrik vulnerability, CVE-2026-66915, affects Joomla sites running Fabrik versions 1.0.0 through 4.6.8. Administrators should verify their installed version and update to Fabrik 4.6.9 or later as soon as possible.
Read more: Fabrik RCE: Update Joomla Sites to 4.6.9 or Later
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
To secure Joomla administrator login access effectively, do not rely on a single setting or a hidden URL. A safer approach combines supported Joomla software, a long and unique password, Multi-factor Authentication (MFA), carefully limited user permissions, clean extension management, prepared recovery options, and hosting-level restrictions where they are operationally appropriate.
This beginner-friendly guide is intended for Joomla administrators and hosting customers working primarily with Joomla 6.1.x and 5.4.x. It explains what each security layer does, how to introduce the layers without locking yourself out, and how to test the result. Joomla uses the term Multi-factor Authentication; the familiar phrase Joomla two factor authentication, or 2FA, refers to the common case in which two factors are used.
Before changing authentication or server rules, make a tested backup, preserve an authenticated administrator session, verify a separate recovery route, and make sure you can reverse hosting-level changes. Administrator login hardening is an ongoing maintenance process, not a one-time installation task.
Read more: Secure Joomla Administrator Login: A Layered Security Guide
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Balbooa Forms (com_baforms) versions before 2.4.1 are affected by CVE-2026-56291, an actively exploited unauthenticated file-upload vulnerability that can lead to remote code execution. Joomla administrators should identify exposed installations, update to 2.4.1 or later without delay, and review affected sites for signs of unauthorised uploads or code execution.
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
xmr-pay packages described for HikaShop and VirtueMart give Joomla shop operators a route to evaluate Monero as a payment option without treating the integration as a security disclosure. This practical guide focuses on planning, staging-site validation, operational controls and a cautious production rollout for stores that decide the payment method suits their business.
Read more: Accept Monero on Joomla with xmr-pay for HikaShop and VirtueMart