

By Bill Toulas · July 11, 2026
The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins.
The government agency says that many Australian businesses have already been affected by the malicious activity, with webshells being deployed on their sites.
Webshells provide persistent access to the compromised sites and allow threat actors to disrupt services, steal credentials, plant additional malware, and move deeper into the network.
"A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with many small- to medium-sized Australian businesses impacted." — ACSC
As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins.
The ACSC noted that the campaign might be supported by AI, which typically helps threat actors accelerate attacks and scale the exploitation of emerging flaws.
According to the agency, the activity leverages flaws in several CMS platforms and plugins, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE. ACSC lists the following products exploited in the campaign:
Is your workplace CMS — whether WordPress, Joomla, Craft CMS, or another platform — protected against the vulnerabilities being actively exploited in this global campaign?
Many small- to medium-sized businesses don't know they're exposed until it's too late. Webshells can be silently deployed, giving attackers persistent access to disrupt services, steal credentials, and move deeper into your network.
We scan your CMS, plugins, and themes for known CVEs and misconfigurations before attackers find them.
We identify unauthorized files and suspicious activity already present on your web server.
We provide actionable recommendations to lock down directories, restrict access, and keep your site secure.
Website administrator are recommended to apply the latest security updates for their CMS, themes, and plugins, remove unused components, and enable automatic updates where possible.
It is also recommended to make web directories read-only when possible, monitor for unauthorized file creation, restrict access to sensitive directories, and block unexpected spawning of child processes on the web server.
Apply the latest security updates for their CMS, themes, and plugins, remove unused components, and enable automatic updates where possible.
Make web directories read-only when possible, monitor for unauthorized file creation, and restrict access to sensitive directories.
Block unexpected spawning of child processes on the web server.
Australia warns of global campaign targeting vulnerable CMS platforms