Government Advisory

Widespread Attacks Target Website Content Management Systems – Is Your Site at Risk?

ACSC · 9 July 2026
Key Takeaway Update your CMS platform, plugins, and themes to the latest versions now, and ask your web host or developer to confirm your site isn't running vulnerable software.

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has issued a critical alert about an ongoing, large-scale exploitation campaign targeting website content management systems (CMS) worldwide, with confirmed activity in Australia. CMS platforms like WordPress, Joomla, and similar tools power a huge proportion of business websites, making them an attractive target for attackers looking to compromise many sites at once.

While the ACSC has not detailed the specific vulnerabilities being exploited, campaigns of this nature typically involve attackers scanning the internet for outdated or misconfigured CMS installations, plugins, and themes. Once compromised, websites can be used to host malicious content, redirect visitors to scam pages, steal customer data, or serve as a foothold for further attacks against the business or its customers.

For small and medium businesses that rely on a CMS-powered website for e-commerce, bookings, or customer engagement, this alert is a timely reminder that website infrastructure needs the same security attention as email and endpoint devices. Businesses should check with their web developer or hosting provider to confirm their CMS, plugins, and themes are fully patched and monitor for signs of unusual website behaviour.

CMS security website vulnerabilities ACSC alert

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.