CVE-2026-94132: Acymailing.com Acymailing Enterprise Extension For Joomla

Critical severity, CVSS 9.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.

Affected products

  • Acymailing.com Acymailing Enterprise Extension For Joomla: version 6.0.0-11.0.5 only

Published 2026-09-26. Last modified 2026-09-29.