CVE-2026-67282Disclosure

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-12); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-08-12: 3Mentions · 2026-08-13: 2Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-13: 1Patch / Workaround · 2026-08-12: 2Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 1Technical Details · 2026-08-20: 108-1208-1308-20
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
General
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-123
Disclosure1Patch2
2026-08-132
General1PoC1
2026-08-201
Disclosure1
Full discourse6 posts
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-67282 [HIGH PRIORITY] #Joomla Extension - https://fabrikar.com - Unauthenticated remote code execution in Fa... 🔗 https://exploitgrid.net/cve/CVE-2026-67282

    Post summary

    CVE-2026-67282, a high‑priority unauthenticated RCE in a Joomla extension from Fabrikar, has a PoC available on ExploitGrid. No patch or active exploitation report is cited.

    1000036
    30 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2024-27253 CVE-2026-67282 CVE-2026-73299 CVE-2026-16860 CVE-2026-19656 ..🧵👇

    Post summary

    The post merely enumerates several CVE identifiers without offering any additional details, context, or actionable information.

    1000043
    30 followersView on X
  • Proxima Cyber Security@ProximaCyber_
    Disclosure

    NÖVBƏTİ UĞURUMUZ - CVE-2026-67282 Joomla üçün Fabrik extension-da kritik təhlükəsizlik zəifliyi aşkar edilib! CVE: CVE-2026-67282 CVSS: 10.0 -Critical Zəiflik: Unauthenticated Remote Code Execution (RCE) Təsirə məruz qalan versiyalar: ≤ 4.6.7 Məlumat üçün:https://lnkd.in/dyaVGP9S https://t.co/rAWXBXHsOy

    Post summary

    The post announces a critical unauthenticated RCE vulnerability (CVE-2026-67282) in the Joomla Fabrik extension, providing its CVSS score, affected versions, and links for additional information.

    0000032
    3 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Joomla ❗ CVE-2026-67282 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-joomla-2/ https://t.co/H67tEuJfvP

    Post summary

    The tweet announces a newly disclosed vulnerability (CVE‑2026‑67282) in Joomla products, linking to CERT information but providing no technical or exploitation details.

    00000206
    6.7K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🧩 Fabrik Joomla extension: unauthenticated RCE via the frontend listfilter model. No login needed. CVE-2026-67282 hits CVSS 10 — upgrade to 4.6.8 now. #cybersecurity #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-67282?utm_campaign=x https://t.co/SA3TGCvZXK

    Post summary

    The tweet highlights a critical unauthenticated RCE in the Fabrik Joomla extension (CVE-2026-67282) and urges users to upgrade to version 4.6.8, but does not provide PoC or exploitation evidence.

    0000093
    878 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Joomla Fabrik Unauthenticated RCE via listfilter Model (CVE-2026-67282) Fabrik extension for Joomla exposes an unauthenticated RCE path by abusing the frontend listfilter model; crafted requests trigger arbitrary code execution in the listfilter handling flow. Impact: full server compromise under the webserver user. 👉Affected: Joomla Fabrik extension < 4.6.8 | Upgrade to 4.6.8

    Post summary

    A critical Joomla Fabrik RCE vulnerability (CVE-2026-67282) allows unauthorized code execution via the listfilter model; users are advised to upgrade to version 4.6.8 to mitigate the risk.

    0000075
    288 followersView on X

Explore more