2026-07-11HIGHTwo more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS 10.0)
Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave
cve · CVE-2026-57827
Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
Two more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector · regions: europe, switzerland
Sources cited
4
3 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-57827, newest first. Check the date before acting on an older one.
- Update RSFiles! (com_rsfiles) to ≥ 1.17.12 on every Joomla site now (this is unauthenticated RCE reachable by anyone, not a maintenance-window update) then check the component's web-root /downloads directory for stray .php/.phtml files and review admin accounts for tampering.2026-07-11CVE-2026-57827 +1
- Update Phoca Download (com_phocadownload) to ≥ 6.1.3; if the frontend member-upload feature was enabled (it is off by default), treat as a priority and hunt the user-upload folder for web shells. Disable member-upload where not required to remove the exposure entirely.2026-07-11CVE-2026-57827 +1
- As defense-in-depth against the whole wave, configure the web server to deny script execution in Joomla extension upload/download directories.2026-07-11CVE-2026-57827 +1
Defender insights
What each entry about CVE-2026-57827 tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828 · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828 · ATT&CK page ↗
Entries about Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Joomla extension file-upload RCE wave×1
- Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0)×1
- Phoca Download for Joomla×1
- RSFiles! for Joomla×1
Where this entity is cited
Source distribution
- mysites.guru2 (50%)
- cisa.gov1 (25%)
- rsjoomla.com1 (25%)
External references
All cited sources (4)
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/
- cisa.govCISA KEVhttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- rsjoomla.comRSJoomla! (vendor)https://www.rsjoomla.com/blog/view/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html