The point is the operating system is centralized enforcement end points. And if [an] attacker put his code on that level, in ...
CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request.