1. Stay on a supported, patched version
Update first: no hardening step compensates for a known, published vulnerability. Joomla 6.1.4 and 5.4.9 fixed seven security issues announced between 10 and 16 September 2026, including an MFA bypass through "remember me" cookies and missing ACL checks on Web Services edit tasks (Joomla Security Centre).
|
Series |
Bugfix support ends |
Security-only support ends |
|---|---|---|
|
Joomla 6.x |
17 October 2028 |
16 October 2029 |
|
Joomla 5.x |
13 October 2026 |
12 October 2027 |
Source: Joomla roadmap. Joomla 5 leaves regular bugfix support on 13 October 2026, so plan the move to 6.x now rather than in 2027.
What to do
- Keep core on the latest release of a supported series. Check from the shell with
php cli/joomla.php core:update:check(tested: it reported "You already have the latest Joomla version 6.1.4"). - Check extensions with
php cli/joomla.php update:extensions:check, or in System → Update → Extensions. Treat any extension without updates for 12+ months as a risk to review. - Leave the update channel on Default (
php cli/joomla.php core:update:channelshows it). Never run Testing or custom channels on production. - Subscribe to the Security Centre feed so you learn about fixes on release day, not from a compromise.
If you manage many sites, a central update platform does the same job at scale. The point is speed: the window between a Joomla security release and automated scanning for it is short.
