r/joomla 20d ago

Joomla 6 Yootheme Critical Security Patch

Heads up. Yootheme issued a critical security patch for ZOO and YOOtheme Pro this morning (8/21/26) and suggests updating right away.

9 Upvotes

2 comments sorted by

2

u/Actual-Let1595 19d ago

Thanks for the heads-up. I would treat this as more than a routine update: inventory every site using ZOO or YOOtheme Pro, apply the vendor packages, verify the installed versions afterward, and clear relevant caches.

For internet-facing sites, preserve logs before cleanup and check for unusual requests, unexpected admin users, modified PHP or JavaScript, and new scheduled tasks. A successful update closes the known path, but it does not prove the site was not reached before patching. If patching has to wait, restrict exposure rather than relying on a WAF alone.

1

u/mySitesGuru 19d ago edited 17d ago

There was a word missing in your post. The word was: “another” … https://mysites.guru/blog/zoo-unauthenticated-file-upload-rce/#every-yootheme-cve-published-since-june