CVE-2026-21628Disclosure(templaza / astroid_framework)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch templaza astroid_framework systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • astroid_framework

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-05); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
astroid_framework

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-05: 3Mentions · 2026-03-06: 1Mentions · 2026-03-20: 1Mentions · 2026-04-11: 1Active Exploitation · 2026-03-20: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-03-05: 3Technical Details · 2026-03-06: 1Technical Details · 2026-04-11: 103-0503-0603-2004-11
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
Active Exploitation
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-053
Disclosure3
2026-03-061
Patch1
2026-03-201
Active Exploitation1
2026-04-111
Patch1
Full discourse6 posts
  • Günter Born@etguenni
    Active Exploitation

    Jemand mit #Joomla im Web unterwegs? Im #Astroid Framework gibt es eine kritische Sicherheitslücke, die gerade aktiv für Angriffe genutzt wird. https://borncity.com/blog/2026/03/20/joomla-schwachstelle-cve-2026-21628-im-astroid-framework-wird-angegriffen/

    Post summary

    The post signals that CVE-2026-21628 in the Astroid framework is being actively exploited, yet it offers no technical details, PoC, or patch information.

    01030209
    2.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical improperly secured file management vulnerability in #Astroid Framework #Joomla #CVE-2026-21628 CVSS: 10.0 A remote, unauthenticated attacker can exploit it for remote code execution #RCE! https://ccb.belgium.be/advisories/warning-critical-improperly-secured-file-management-astroid-framework-joomla-can-lead #Patch #Patch #Patch

    Post summary

    The advisory warns of a critical RCE (CVSS 10.0) in the Astroid Framework for Joomla (CVE‑2026‑21628) and emphasizes the need to apply a patch.

    02011351
    7.2K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    ICYMI: CVE-2026-21628 - CVSS 10.0 critical auth bypass in Astroid Framework for Joomla. Attackers upload backdoors without logging in. Update to 3.3.13 now. https://mysites.guru/blog/astroid-framework-security-vulnerability/?utm_source=twitter&utm_medium=social https://t.co/kVCqanGwLi

    Post summary

    The tweet highlights a critical auth bypass (CVE-2026-21628) in Joomla's Astroid Framework and directs users to the 3.3.13 patch.

    00101148
    2.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21628 Unauthenticated Remote Code Execution via Unrestricted File Upload Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21628

    Post summary

    The post announces CVE-2026-21628, an unauthenticated RCE via unrestricted file upload, providing only basic technical details without evidence of exploitation or patches.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21628 A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution. https://www.cve.org/CVERecord?id=CVE-2026-21628

    Post summary

    The post announces CVE-2026-21628 as a remote code execution flaw due to unsafe file uploads by unauthenticated users, but provides no PoC, exploit, patch info, or evidence of active exploitation.

    00000104
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-21628 - Extension - http://astroidframe.work - Unauthenticated Remote Code Execution in Astroid Framework 2.0.0 - 3.3.10 for Joomla Intel Report: https://ift.tt/bsaTWRr

    Post summary

    A new unauthenticated RCE vulnerability (CVE‑2026‑21628) in Astroid Framework 2.0.0‑3.3.10 for Joomla is announced, but the post provides no PoC, exploit, or patch details.

    0000045
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptemplazaastroid_framework-joomla\!-

Explore more