The Joomla team has released a patch for a serious security vulnerability affecting all versions of the web site. The vulnerability has a high severity as it allows anyone to create a user remotely and specify the desired group permission to it, including administrator. The attackers will likely try to reverse the patch to find out how they can leverage it to create admin users on sites in order to compromise them for malware distribution, phishing, DDoS, and more. The good news is that if you have your site behind our Sucuri Firewall you are protected against this issue.”]
Source: https://blog.sucuri.net/2016/10/joomla-account-creation-vulnerability.html