Joomla has emailed a security announcement. If you use Joomla for your site, please check your version and upgrade accordingly.
The announcement is available on their site here:
https://developer.joomla.org/security-centre.html
Quote
Joomla! Security News
________________________________________
[20161003] - Core - Account Modifications
Posted: 27 Oct 2016 12:00 PM PDT
-Project: Joomla!
-SubProject: CMS
-Severity: High
-Versions: 3.4.4 through 3.6.3
-Exploit type: Account Modifications
-Reported Date: 2016-October-26
-Fixed Date: 2016-October-25
-CVE Number: CVE-2016-9081
Description
Incorrect use of unfiltered data allows for existing user accounts to be modified; to include resetting their username, password, and user group assignments.
Affected Installs
Joomla! CMS versions 3.4.4 through 3.6.3
Solution
Upgrade to version 3.6.4