AcyMailing Shoots Itself in the Foot With a Vanishing Update Site

AcyMailing 11.1.0 went out on 24 September 2026 with two security fixes, and two days later the Joomla CNA gave them CVE numbers: CVE-2026-94132, a 9.5 Critical file write through mailbox actions, and CVE-2026-94131, a file deletion rated 8.3 High. We covered both in our 11.1.0 post. Since then a proof-of-concept for the first one has been published on GitHub, so updating is no longer a job for next week.
A lot of Joomla sites running AcyMailing will not tell you there is anything to update, though. A Joomla developer pointed out on 30 September that a site on 10.11.1 reports itself up to date, and another found that the update sites were gone from every AcyMailing site they looked after. We traced it to a design choice in AcyMailing’s installer, and to the button almost every Joomla guide tells you to press when updates stop appearing.
TL;DR
- AcyMailing’s Joomla package declares no update server in its XML manifest. Its install script inserts the update site into the database instead.
- Joomla’s Rebuild button in Update Sites deletes every non-core update site and recreates only the ones manifests declare, so it removes AcyMailing’s and cannot put it back.
- With no update site, Joomla reports AcyMailing as up to date on any version, including those below 11.1.0.
- Across the AcyMailing sites mySites.guru monitors, one in four sites still below 11.1.0 has no AcyMailing update site. On 10.11 it is more than half.
- Installing the current package over the top brings the update site back, but every Rebuild deletes it again, over and over, until AcyMailing puts the missing
<updateservers>values in its XML manifest.
Where AcyMailing keeps its Joomla update site
A Joomla extension normally tells Joomla where to look for updates in its XML manifest, in an <updateservers> block. When the extension is installed, Joomla’s own “Extension - Joomla” plugin reads that block and writes the row into #__update_sites. The manifest stays on disk, so Joomla can always rebuild the row from it.
AcyMailing does not do that. We opened all the AcyMailing Joomla packages we could get hold of, from 10.10.2 to 11.1.0, in the Starter, Essential and Enterprise editions, and not one pkg_acymailing.xml or acym.xml contains an <updateservers> element. Instead, the package’s install script, pkg_acymailing.php, does the job itself after every install or update:
// 1 - Clear existing updates on AcyMailing extensions
acym_query('DELETE FROM #__updates WHERE extension_id IN (...)');
// ...deletes every update site linked to AcyMailing's extensions...
// 2 - Add the new update XML
$updateSiteDefinition->location = ACYM_UPDATEME_API_URL
.'public/updatexml/component?extension=acymailing'
.'&cms=joomla&version=latest&level=starter&type=package';
$updateSiteId = acym_insertObject('#__update_sites', $updateSiteDefinition);
The paid editions use level=essential or level=enterprise and add the site’s own URL, which is how Acyba ties the download to a licence. The method is the same, apart from the edition name, in all the packages we checked from 10.10.2 to 11.1.0.
The feed itself works: on 30 September 2026 it answered 11.1.0 for all three editions. The weak point is that the only record of where the feed lives is a database row, and no file on disk can recreate it.
What Joomla’s Rebuild button does to AcyMailing
Joomla has a Rebuild button in the toolbar of System, Update Sites. It was added in 2016 in joomla-cms #9744, described as rebuilding the update sites “from the manifest files”, and the code in UpdatesitesModel::rebuild() does exactly that on Joomla 4, 5 and 6. It deletes every row from #__update_sites, #__update_sites_extensions and #__updates except Joomla’s own core sites, then walks every extension manifest on disk and recreates an update site for each one that has an <updateservers> block. It never runs an extension’s install script.
For most extensions that is harmless, and it is the standard advice when updates go missing. Admin Tools’ documentation sends you to it, Akeeba’s support desk has recommended it since at least 2017, and our post on Joomla update expiry errors suggests a rebuild and re-check too. For AcyMailing it is the one click that removes the update site for good. The row is deleted, there is no manifest to rebuild it from, and from then on Joomla has no feed to ask about AcyMailing. When Joomla has nothing to ask, the Extensions: Update screen shows no AcyMailing update, and the site looks up to date.
Rebuild is not the only way to lose it: deleting the row by hand in the Update Sites view does the same. What makes Rebuild the common cause is timing: it is the step people take when updates look broken, so it tends to happen on the sites that most need an update.
An update site that exists only in the database is one click from gone
If an extension cannot be rebuilt from its manifest, Joomla’s standard repair is what breaks it.
How many AcyMailing sites have lost their update site?
Across the Joomla sites mySites.guru monitors that ran a snapshot in the 14 days to 30 September 2026, one in eight sites running AcyMailing has no AcyMailing update site at all. The sites to worry about are the ones that need 11.1.0 and cannot see it. About 40% of those AcyMailing sites were still below 11.1.0, and among them one in four had no update site. For those sites the Joomla updater is silent about a 9.5 Critical fix.
Broken down by the installed version, the pattern is hard to miss:
| AcyMailing version | Sites with no AcyMailing update site |
|---|---|
| 11.1 | 5% |
| 11.0 | 18% |
| 10.11 | 58% |
| 9.10 | 6% |
The 10.11 figure looks like a bug in that release, but the update-site code in its installer is the same as in 11.1.0. What it shows is a selection effect. Sites that could see updates moved on to 11.0 and 11.1 over the summer. The sites still sitting on 10.11 are, more often than not, the ones whose Joomla stopped hearing about new versions. The older a version looks in your list, the more likely it is that nobody was ever told about the newer one.
How do I get the AcyMailing update site back in Joomla?
Install the current AcyMailing package over the top of the existing install. The package’s install script runs again, clears out any AcyMailing update sites it finds, and inserts a fresh one. Your lists, subscribers, campaigns and settings are untouched, because this is the same process as any normal AcyMailing update, and AcyMailing’s own update guide gives it as the fallback when the updater fails.
- Download the edition the site already runs. Starter is free from acymailing.com; Essential and Enterprise packages are in your AcyMailing account under the licence.
- In the Joomla administrator, go to System, Install, Extensions and upload the package. Do not uninstall AcyMailing first; an install over the top is all it needs.
- Open System, Update Sites and search for AcyMailing. There should be one enabled entry pointing at
api.acymailing.com. - Treat Rebuild as off limits on that site. If you have to use it for another extension, reinstall AcyMailing straight afterwards, every time.
Every Rebuild deletes it again
Reinstalling restores the database row and nothing else. AcyMailing’s XML manifest still has no <updateservers> values, so the next Rebuild deletes the update site again, and so will every Rebuild after that, on every AcyMailing site you look after, until Acyba adds the missing values to the manifest.
Installing 11.1.0 this way also closes the two CVEs, so on a site below 11.1.0 one upload does both jobs. Check any AcyMailing add-ons afterwards: 11.1.0 breaks some older ones with a PHP fatal error.
What mySites.guru sees when Joomla sees nothing
mySites.guru records the installed version of every extension on every connected Joomla site, and compares it with our Joomla vulnerability rules. The AcyMailing rule for versions below 11.1.0 went live on release day. That comparison uses the version number, not Joomla’s update data, so a site with no AcyMailing update site is still flagged as vulnerable on its dashboard and in its audit, even while its own Joomla administrator says there is nothing to do.
What we cannot do for such a site is update it for you. mySites.guru’s one-click updates, bulk updates and automatic extension updates all start from the update Joomla reports, so they need an update site to work from. On a site that has lost it, the vulnerability flag is your warning and the reinstall above is the fix. Once the update site is back, those tools pick AcyMailing up again from the next snapshot.
If you are a subscriber, the AcyMailing extension search lists all your installs grouped by version. A site still showing 10.11 or 11.0 there after this week is worth a closer look. The vulnerable extension list puts it together with every other flagged extension across your sites.
This is the second update-channel failure we have written up today. OrdaSoft fixed a SQL injection and a CVSS 10.0 upload flaw in OS CCK 8.3.16 while its update server kept offering 8.3.14. The two failures differ, and the lesson is the same: a patch that exists does not mean a patch is reaching anyone, so check the installed version, not the update screen.
The fix belongs in AcyMailing’s Joomla manifest
Acyba presumably manages the update site in code because the paid editions need a licence-bound URL, and a URL that differs per site is awkward to write into a manifest that is the same for everyone.
None of that needs the manifest to stay empty. A <updateservers> block in pkg_acymailing.xml pointing at the Starter feed would let Joomla rebuild a working update site, and the install script could go on replacing it with the licensed URL as it does now. Joomla 4 and later also support download keys in the manifest, which is the standard way to attach a licence to an update feed without writing to the database by hand. Either change is a few lines, and either would mean Rebuild repairs AcyMailing instead of breaking it.
Until then, treat “up to date” from a Joomla site running AcyMailing as unconfirmed. Check the version number against 11.1.0 yourself, or let mySites.guru check it for every site you look after.
Timeline
Acyba releases AcyMailing 11.1.0
Two security fixes are listed under Bug fixes, with no advisory. mySites.guru flags every connected Joomla site below 11.1.0 the same day.
The Joomla CNA publishes CVE-2026-94132 and CVE-2026-94131
A public proof-of-concept for CVE-2026-94132 appears on GitHub the same evening.
Joomla developers notice sites that cannot see the update
Sites on older AcyMailing versions report themselves up to date. We trace it to update sites that exist only in the database.
Further Reading
- AcyMailing 11.1.0 Fixes Two Security Flaws - what the update you might not be seeing actually fixes
- AcyMailing changelog - the vendor's release notes, 11.1.0 dated 24 September 2026
- Joomla Help: Extensions: Update Sites - the screen with the Rebuild button
- Akeeba: Working around Joomla's broken extensions updater - another vendor's account of what Rebuild does to update site records
- joomla-cms issue #9744 - where Rebuild was added, described as rebuilding update sites from the manifest files


