Security
AcyMailing update failure can hide critical security fixes
Joomla administrators running AcyMailing below 11.1.0 may not be warned about two security fixes because the extension’s update site can disappear from Joomla’s database.
mySites.guru reports that AcyMailing’s installer adds its update site directly to the database rather than declaring it in the extension manifest. Joomla’s Update Sites “Rebuild” function removes that entry and cannot recreate it, leaving affected installations appearing up to date.
Vendor Acyba released 11.1.0 on 24 September 2026. The release fixes CVE-2026-94132, a file-write vulnerability rated 9.5 Critical, and CVE-2026-94131, a file-deletion vulnerability rated 8.3 High. A public proof of concept is available for the file-write issue; the report does not state that either flaw is being exploited in the wild.
Administrators should check the installed AcyMailing version rather than relying solely on Joomla’s update screen. Install the current package over the existing installation to restore the update entry, without uninstalling first. Avoid using Rebuild afterward, as it will remove the entry again until AcyMailing adds update-server information to its manifest.
Originally reported by mySites.guru.