Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

AcyMailing Shoots Itself in the Foot With a Vanishing Update Site

AcyMailing Shoots Itself in the Foot With a Vanishing Update Site

AcyMailing 11.1.0 went out on 24 September 2026 with two security fixes, and two days later the Joomla CNA gave them CVE numbers: CVE-2026-94132, a 9.5 Critical file write through mailbox actions, and CVE-2026-94131, a file deletion rated 8.3 High. We covered both in our 11.1.0 post. Since then a proof-of-concept for the first one has been published on GitHub, so updating is no longer a job for next week.

A lot of Joomla sites running AcyMailing will not tell you there is anything to update, though. A Joomla developer pointed out on 30 September that a site on 10.11.1 reports itself up to date, and another found that the update sites were gone from every AcyMailing site they looked after. We traced it to a design choice in AcyMailing’s installer, and to the button almost every Joomla guide tells you to press when updates stop appearing.

TL;DR

  • AcyMailing’s Joomla package declares no update server in its XML manifest. Its install script inserts the update site into the database instead.
  • Joomla’s Rebuild button in Update Sites deletes every non-core update site and recreates only the ones manifests declare, so it removes AcyMailing’s and cannot put it back.
  • With no update site, Joomla reports AcyMailing as up to date on any version, including those below 11.1.0.
  • Across the AcyMailing sites mySites.guru monitors, one in four sites still below 11.1.0 has no AcyMailing update site. On 10.11 it is more than half.
  • Installing the current package over the top brings the update site back, but every Rebuild deletes it again, over and over, until AcyMailing puts the missing <updateservers> values in its XML manifest.

Where AcyMailing keeps its Joomla update site

A Joomla extension normally tells Joomla where to look for updates in its XML manifest, in an <updateservers> block. When the extension is installed, Joomla’s own “Extension - Joomla” plugin reads that block and writes the row into #__update_sites. The manifest stays on disk, so Joomla can always rebuild the row from it.

AcyMailing does not do that. We opened all the AcyMailing Joomla packages we could get hold of, from 10.10.2 to 11.1.0, in the Starter, Essential and Enterprise editions, and not one pkg_acymailing.xml or acym.xml contains an <updateservers> element. Instead, the package’s install script, pkg_acymailing.php, does the job itself after every install or update:

// 1 - Clear existing updates on AcyMailing extensions
acym_query('DELETE FROM #__updates WHERE extension_id IN (...)');
// ...deletes every update site linked to AcyMailing's extensions...

// 2 - Add the new update XML
$updateSiteDefinition->location = ACYM_UPDATEME_API_URL
    .'public/updatexml/component?extension=acymailing'
    .'&cms=joomla&version=latest&level=starter&type=package';
$updateSiteId = acym_insertObject('#__update_sites', $updateSiteDefinition);

The paid editions use level=essential or level=enterprise and add the site’s own URL, which is how Acyba ties the download to a licence. The method is the same, apart from the edition name, in all the packages we checked from 10.10.2 to 11.1.0.

The feed itself works: on 30 September 2026 it answered 11.1.0 for all three editions. The weak point is that the only record of where the feed lives is a database row, and no file on disk can recreate it.

What Joomla’s Rebuild button does to AcyMailing

Joomla has a Rebuild button in the toolbar of System, Update Sites. It was added in 2016 in joomla-cms #9744, described as rebuilding the update sites “from the manifest files”, and the code in UpdatesitesModel::rebuild() does exactly that on Joomla 4, 5 and 6. It deletes every row from #__update_sites, #__update_sites_extensions and #__updates except Joomla’s own core sites, then walks every extension manifest on disk and recreates an update site for each one that has an <updateservers> block. It never runs an extension’s install script.

For most extensions that is harmless, and it is the standard advice when updates go missing. Admin Tools’ documentation sends you to it, Akeeba’s support desk has recommended it since at least 2017, and our post on Joomla update expiry errors suggests a rebuild and re-check too. For AcyMailing it is the one click that removes the update site for good. The row is deleted, there is no manifest to rebuild it from, and from then on Joomla has no feed to ask about AcyMailing. When Joomla has nothing to ask, the Extensions: Update screen shows no AcyMailing update, and the site looks up to date.

Rebuild is not the only way to lose it: deleting the row by hand in the Update Sites view does the same. What makes Rebuild the common cause is timing: it is the step people take when updates look broken, so it tends to happen on the sites that most need an update.

An update site that exists only in the database is one click from gone

If an extension cannot be rebuilt from its manifest, Joomla’s standard repair is what breaks it.

How many AcyMailing sites have lost their update site?

Across the Joomla sites mySites.guru monitors that ran a snapshot in the 14 days to 30 September 2026, one in eight sites running AcyMailing has no AcyMailing update site at all. The sites to worry about are the ones that need 11.1.0 and cannot see it. About 40% of those AcyMailing sites were still below 11.1.0, and among them one in four had no update site. For those sites the Joomla updater is silent about a 9.5 Critical fix.

Broken down by the installed version, the pattern is hard to miss:

AcyMailing versionSites with no AcyMailing update site
11.15%
11.018%
10.1158%
9.106%

The 10.11 figure looks like a bug in that release, but the update-site code in its installer is the same as in 11.1.0. What it shows is a selection effect. Sites that could see updates moved on to 11.0 and 11.1 over the summer. The sites still sitting on 10.11 are, more often than not, the ones whose Joomla stopped hearing about new versions. The older a version looks in your list, the more likely it is that nobody was ever told about the newer one.

How do I get the AcyMailing update site back in Joomla?

Install the current AcyMailing package over the top of the existing install. The package’s install script runs again, clears out any AcyMailing update sites it finds, and inserts a fresh one. Your lists, subscribers, campaigns and settings are untouched, because this is the same process as any normal AcyMailing update, and AcyMailing’s own update guide gives it as the fallback when the updater fails.

  1. Download the edition the site already runs. Starter is free from acymailing.com; Essential and Enterprise packages are in your AcyMailing account under the licence.
  2. In the Joomla administrator, go to System, Install, Extensions and upload the package. Do not uninstall AcyMailing first; an install over the top is all it needs.
  3. Open System, Update Sites and search for AcyMailing. There should be one enabled entry pointing at api.acymailing.com.
  4. Treat Rebuild as off limits on that site. If you have to use it for another extension, reinstall AcyMailing straight afterwards, every time.

Every Rebuild deletes it again

Reinstalling restores the database row and nothing else. AcyMailing’s XML manifest still has no <updateservers> values, so the next Rebuild deletes the update site again, and so will every Rebuild after that, on every AcyMailing site you look after, until Acyba adds the missing values to the manifest.

Installing 11.1.0 this way also closes the two CVEs, so on a site below 11.1.0 one upload does both jobs. Check any AcyMailing add-ons afterwards: 11.1.0 breaks some older ones with a PHP fatal error.

What mySites.guru sees when Joomla sees nothing

mySites.guru records the installed version of every extension on every connected Joomla site, and compares it with our Joomla vulnerability rules. The AcyMailing rule for versions below 11.1.0 went live on release day. That comparison uses the version number, not Joomla’s update data, so a site with no AcyMailing update site is still flagged as vulnerable on its dashboard and in its audit, even while its own Joomla administrator says there is nothing to do.

What we cannot do for such a site is update it for you. mySites.guru’s one-click updates, bulk updates and automatic extension updates all start from the update Joomla reports, so they need an update site to work from. On a site that has lost it, the vulnerability flag is your warning and the reinstall above is the fix. Once the update site is back, those tools pick AcyMailing up again from the next snapshot.

If you are a subscriber, the AcyMailing extension search lists all your installs grouped by version. A site still showing 10.11 or 11.0 there after this week is worth a closer look. The vulnerable extension list puts it together with every other flagged extension across your sites.

This is the second update-channel failure we have written up today. OrdaSoft fixed a SQL injection and a CVSS 10.0 upload flaw in OS CCK 8.3.16 while its update server kept offering 8.3.14. The two failures differ, and the lesson is the same: a patch that exists does not mean a patch is reaching anyone, so check the installed version, not the update screen.

The fix belongs in AcyMailing’s Joomla manifest

Acyba presumably manages the update site in code because the paid editions need a licence-bound URL, and a URL that differs per site is awkward to write into a manifest that is the same for everyone.

None of that needs the manifest to stay empty. A <updateservers> block in pkg_acymailing.xml pointing at the Starter feed would let Joomla rebuild a working update site, and the install script could go on replacing it with the licensed URL as it does now. Joomla 4 and later also support download keys in the manifest, which is the standard way to attach a licence to an update feed without writing to the database by hand. Either change is a few lines, and either would mean Rebuild repairs AcyMailing instead of breaking it.

Until then, treat “up to date” from a Joomla site running AcyMailing as unconfirmed. Check the version number against 11.1.0 yourself, or let mySites.guru check it for every site you look after.

Timeline

  1. Acyba releases AcyMailing 11.1.0

    Two security fixes are listed under Bug fixes, with no advisory. mySites.guru flags every connected Joomla site below 11.1.0 the same day.

  2. The Joomla CNA publishes CVE-2026-94132 and CVE-2026-94131

    A public proof-of-concept for CVE-2026-94132 appears on GitHub the same evening.

  3. Joomla developers notice sites that cannot see the update

    Sites on older AcyMailing versions report themselves up to date. We trace it to update sites that exist only in the database.

Further Reading

Frequently Asked Questions

Why does Joomla say AcyMailing is up to date when 11.1.0 is out?
Usually because the site has no AcyMailing update site any more. AcyMailing does not declare one in its XML manifest; its installer inserts it into the database. Anything that rebuilds update sites from manifests, such as the Rebuild button in Joomla's Update Sites view, deletes it and cannot recreate it, so Joomla has nothing to check and reports no update.
How do I get the AcyMailing update site back?
Install the current AcyMailing package over the top of the existing install. The package's install script runs again and inserts the update site. Your lists, subscribers and settings stay where they are, as they do on any normal AcyMailing update. That repair lasts only until the next Rebuild: every Rebuild deletes the update site again, over and over, until AcyMailing adds the missing updateservers values to its XML manifest.
Should I click Rebuild in Joomla's Update Sites view?
Not on a site that runs AcyMailing. Rebuild deletes every non-core update site and recreates only those declared in extension manifests, and AcyMailing declares none, so every Rebuild deletes its update site, every time. Reinstalling AcyMailing brings it back until the next one.
Which AcyMailing versions are affected by this?
Every package we have checked, from 10.10.2 to 11.1.0 across the Starter, Essential and Enterprise editions, adds its update site from PHP and ships no updateservers element in its manifest. We have not checked packages older than 10.10.2.
Is AcyMailing below 11.1.0 dangerous?
Yes. 11.1.0 fixes CVE-2026-94132, rated 9.5 Critical, which lets anyone able to email a mailbox monitored over POP3 write a PHP file into the web root, and CVE-2026-94131, a file deletion rated 8.3 High. A public proof-of-concept for CVE-2026-94132 has been on GitHub since 26 September 2026.
Does mySites.guru still flag AcyMailing when the update site is gone?
Yes. The vulnerability flag compares the installed AcyMailing version with our vulnerability rules, so it does not depend on the site's update sites. mySites.guru's one-click and automatic updates do depend on Joomla reporting the update, so a site with no update site needs the package reinstalled first.
EU icon: AI MODIFIEDWritten and edited by a human, with AI assistance. Our approach to AI

What our users say

Cheryl Farr
Cheryl Farr
★★★★★

My site was infected and I was at a total loss on what to do. Phil had me fixed up in a remarkably short amount of time. He went above and beyond anything I had hoped for to get everything up and running correctly.

Read more reviews
Elke Alberth
Elke Alberthmedia sued
★★★★★

I don't know how I could manage all my clients' websites without mysites.guru. Plugins are updated with just a few clicks, and the alerts about malicious files are invaluable! Thanks!!!

Read more reviews

Read all 285 reviews →

Ready to Take Control?

Start with a free site audit. No credit card required.

Get Your Free Site Audit