CVE-2026-74803Patch

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-08-19); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-19: 2Mentions · 2026-08-22: 1Patch / Workaround · 2026-08-19: 2Patch / Workaround · 2026-08-22: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-22: 108-1908-22
Signal classification1 categories
Patch
3100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-192
Patch2
2026-08-221
Patch1
Full discourse3 posts
  • YOOtheme@yootheme
    Patch

    🚨 Critical Security update for ZOO We fixed 3 vulnerabilities: CVE-2026-74803 – Arbitrary file upload CVE-2026-74804 – SQL injection CVE-2026-75114 – External redirects Update ZOO immediately to ZOO 4.1.64.

    Post summary

    ZOO released critical patch 4.1.64 to fix three vulnerabilities: arbitrary file upload (CVE-2026-74803), SQL injection (CVE-2026-74804), and external redirects (CVE-2026-75114).

    11040576
    13.9K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📂 CVE-2026-74803: YOOtheme Zoo &lt; 4.1.64 allows unauthenticated arbitrary file upload. The image element accepts any file when Content-Type falls within the image MIME group. CVSS 10. Patch to 4.1.64 now. #cybersecurity #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-74803?utm_campaign=x https://t.co/G0SX7Ju6hZ

    Post summary

    The tweet reports CVE-2026-74803, an unauthenticated arbitrary file upload vulnerability (CVSS 10) in YOOtheme Zoo versions before 4.1.64, and announces that a patch is now available.

    00000109
    878 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - YOOtheme Zoo for Joomla Unauthenticated Arbitrary File Upload (CVE-2026-74803) The Zoo extension for Joomla (by YOOtheme) before 4.1.64 lets its image element accept arbitrary files whenever the client-supplied Content-Type header falls within the image MIME group. Because validation trusts the attacker-controlled Content-Type instead of the real file contents, an unauthenticated attacker can upload a PHP file disguised as an image. On a PHP CMS like Joomla, that leads directly to code execution and full site takeover. It requires no authentication and no user interaction and scores the maximum CVSS 10.0. 👉Upgrade the Zoo extension to 4.1.64, and check internet-facing Joomla sites for suspicious uploaded files/webshells.

    Post summary

    The post announces a critical unauthenticated arbitrary file upload vulnerability (CVE‑2026‑74803) in YOOtheme Zoo for Joomla, provides technical details and a CVSS 10.0 score, and recommends upgrading to version 4.1.64 for remediation.

    00000107
    292 followersView on X

Explore more