CVE-2026-73373 is an unrestricted dangerous-file upload vulnerability in Joomla! Core and the Joomla! Framework Filesystem package. The default dangerous-file extension list omitted SHTML, permitting an authorized uploader to submit SHTML content where upload controls otherwise block executable or script-interpreted file types. If the deployment's web server is configured to process uploaded SHTML content, the uploaded content can be executed server-side. Reported affected ranges include Joomla! CMS 1.0.0 through 5.4.6 and 6.0.0 through 6.1.2, and Joomla! Framework Filesystem 1.0.0 through 3.3.0 and 4.0.0 through 4.2.0. Some vulnerability metadata instead describes the first CMS range as extending through 5.4.7; deployments should update beyond 5.4.7 rather than rely on that discrepancy.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file Python/PHP repository is an operational Joomla exploitation suite. CVE-2026-Joomla-Suite.py is the command-line entry point: it accepts one target or a target list, can fingerprint installed extensions, supports concurrent scanning, optional proxying and JSON output, and invokes the modules in joomla_exploits.py. It loads payloads/x7-panel.php and attempts the listed extension-specific CVE modules in sequence or a module selected with --cve. Successful deployments are logged locally in panels_joomla.txt and scan_joomla_live.log. The suite claims seven unauthenticated extension paths and includes an additional credential-dependent CVE-2026-73373/com_media path in code. The PHP payload is a functional web shell rather than a benign proof-of-concept: it exposes unauthenticated command execution, filesystem reconnaissance, and arbitrary file-writing/upload features. The only Python dependency is requests; winrarzips_brand.py provides presentation/banner code. CVE and affected-version claims are repository assertions; only the SP LMS Joomla <5.2.2 condition is explicitly stated in the supplied content.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unrestricted SHTML-file upload vulnerability in Joomla! Core. Because SHTML was omitted from the default dangerous-file list, an attacker could potentially achieve code execution on servers configured to execute uploaded SHTML files.
An unrestricted file upload vulnerability in Joomla! Core caused by SHTML files not being included in the default dangerous file list, which could lead to code execution on servers that execute such files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.