{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aacymailingenterprise/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:acymailing:enterprise:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-94132"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AcyMailing Enterprise (\u003c 11.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","joomla","web-application"],"_cs_type":"advisory","_cs_vendors":["AcyMailing"],"content_html":"\u003cp\u003eCVE-2026-94132 is a critical remote code execution (RCE) vulnerability affecting AcyMailing Enterprise for Joomla, versions 11.0.5 and earlier. The flaw exists because the plugin fails to perform file extension validation when processing MIME attachments from mailboxes configured in POP3 mode. When the plugin processes incoming emails to manage subscriptions or other mailbox actions, it saves attachments directly into the publicly accessible directory '/media/com_acym/upload/'. An attacker who identifies a Joomla site using this plugin can exploit this by sending an email containing a malicious PHP script as an attachment to the mailbox monitored by the application. Once the application retrieves the email via POP3, it automatically writes the file to the web root, allowing the attacker to trigger the code via a direct HTTP request. A working proof-of-concept exploit is publicly available, increasing the risk for organizations that have not yet applied the 11.1.0 security update.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target Joomla site utilizing AcyMailing Enterprise with POP3 mailbox integration enabled.\u003c/li\u003e\n\u003cli\u003eThe attacker drafts an email containing a malicious PHP payload as a MIME attachment.\u003c/li\u003e\n\u003cli\u003eThe attacker sends the crafted email to the address monitored by the target's AcyMailing POP3 configuration.\u003c/li\u003e\n\u003cli\u003eThe AcyMailing plugin connects to the POP3 server and retrieves the malicious email.\u003c/li\u003e\n\u003cli\u003eThe plugin parses the MIME attachment and saves the file to the web-accessible directory: /media/com_acym/upload/.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates via browser or command-line tool to the path of the saved file (e.g., \u003ca href=\"https://target.example/media/com_acym/upload/payload.php\"\u003ehttps://target.example/media/com_acym/upload/payload.php\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eThe web server executes the attacker's PHP script, resulting in remote code execution on the underlying server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full remote code execution, enabling attackers to take control of the web server. This can result in unauthorized data access, exfiltration of sensitive Joomla database information, modification of website content, or the establishment of a persistent backdoor for future access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching and configuration hardening to mitigate the risks associated with CVE-2026-94132.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade AcyMailing Enterprise to version 11.1.0 or later immediately to patch the missing file extension validation.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the POP3 mailbox attachment handling feature or switch the mailbox configuration to IMAP mode if the business allows.\u003c/li\u003e\n\u003cli\u003eImplement a restrictive .htaccess or Nginx configuration to deny execution of scripts within the /media/com_acym/upload/ directory.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for HTTP GET requests targeting the /media/com_acym/upload/ directory, particularly for .php files, to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T21:45:12Z","date_published":"2026-09-26T21:45:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94132/","summary":"A vulnerability in AcyMailing Enterprise (CVE-2026-94132) allows unauthenticated remote code execution by sending malicious MIME attachments to a POP3-monitored mailbox.","title":"Remote Code Execution in AcyMailing Enterprise via CVE-2026-94132","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94132/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:acymailing:enterprise:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}