OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-94132 (CVSS 9.5)

NVD · officialPublished Sep 26, 2026Risk 50/100

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.

CVSS
9.5
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source