The German authority warns about security vulnerabilities in popular CMS and recommends prompt updates

The Data Protection and Transparency Officer of Saxony reported an increase in data breach notifications in July and August, due to exploitation of security vulnerabilities in content management systems.

This increase concerns hacked web hosting instances using content management systems (CMS) such as WordPress and Joomla. Critical vulnerabilities, notably CVE-2026-60137 and CVE-2026-63030 for WordPress and CVE-2026-48907 for Joomla, were quickly exploited by automated attacks after their disclosure, affecting sites of schools, associations, and small and medium-sized enterprises. These attacks can lead to unauthorized access to personal data, potentially triggering notification obligations under Articles 33 and 34 of the GDPR. The authority reminds website operators of the importance of applying security updates without delay, as a delay of a few days can cause significant risks. Patches for the mentioned vulnerabilities being available, it is recommended to verify that systems and their extensions are up to date.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire