CVE-2026-94132: Acymailing.com Acymailing Enterprise Extension For Joomla
Critical severity, CVSS 9.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.
Affected products
- Acymailing.com Acymailing Enterprise Extension For Joomla: version 6.0.0-11.0.5 only
Published 2026-09-26. Last modified 2026-09-29.