Critical severity9.8CISA KEVNVD Advisory· Published Jun 20, 2026· Updated Jul 11, 2026
CVE-2026-48939
CVE-2026-48939
Description
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- mysites.guru/blog/icagenda-zero-day-file-upload-rce/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.icagenda.comnvdProduct
- www.icagenda.com/docs/changelog/icagenda-3-9-15nvdRelease Notes
- www.icagenda.com/docs/changelog/icagenda-4-0-8nvdRelease Notes
News mentions
6- Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesThe Register Security · Jul 14, 2026
- CISA warns of actively exploited RCE flaws in Joomla extensionsBleepingComputer · Jul 13, 2026
- CISA Warns of Joomla Sites Running iCagenda or Balbooa Exploited in AttacksCyber Security News · Jul 13, 2026
- Organizations Warned of Exploited Joomla Extension VulnerabilitiesSecurityWeek · Jul 13, 2026
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe Hacker News · Jul 13, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts