CVE-2026-48908Active Exploitation(ollyo / sp_page_builder)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch ollyo sp_page_builder systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sp_page_builder

Threat summary

  • Active exploitation appears in 27 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 46 mentions across 24 observed days

What's happening

  • Active exploitation reported across 27 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 31 signals
  • Disclosure: 8 classified signals
  • General: 4 classified signals
  • Peaked 13d ago at 11 mentions (2026-07-08); latest day: 2
  • 46 total mentions across 24 days

Affected systems

Vendors
Products
sp_page_builder

Deep dive

Activity timeline46 mentions / 24d
036811Mentions · 2026-06-20: 2Mentions · 2026-06-21: 1Mentions · 2026-06-22: 2Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-07-03: 1Mentions · 2026-07-05: 1Mentions · 2026-07-07: 1Mentions · 2026-07-08: 11Mentions · 2026-07-09: 1Mentions · 2026-07-10: 3Mentions · 2026-07-12: 1Mentions · 2026-07-13: 1Mentions · 2026-07-15: 2Mentions · 2026-07-16: 1Mentions · 2026-07-20: 1Mentions · 2026-07-21: 1Mentions · 2026-07-23: 7Mentions · 2026-07-24: 1Mentions · 2026-08-01: 1Mentions · 2026-08-27: 1Mentions · 2026-09-18: 2PoC Mentioned / Linked · 2026-06-22: 2PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-10: 2Exploit Tool / Code · 2026-06-22: 2Exploit Tool / Code · 2026-07-10: 2Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 6Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-10: 2Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-07-15: 2Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-07-23: 6Active Exploitation · 2026-07-24: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 4Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-16: 1Technical Details · 2026-06-20: 2Technical Details · 2026-06-22: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-08: 8Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 3Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-15: 2Technical Details · 2026-07-16: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-24: 1Technical Details · 2026-08-01: 1Technical Details · 2026-08-27: 106-2006-2206-2506-2707-0507-0807-1007-1307-1607-2107-2408-2709-18
Signal classification6 categories
Active Exploitation
2556.8%
Disclosure
818.2%
General
49.1%
Patch
49.1%
PoC
24.5%
Exploit
12.3%
Referenced assets49 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-202
Disclosure1General1
2026-06-211
Active Exploitation1
2026-06-222
PoC2
2026-06-241
Active Exploitation1
2026-06-251
Active Exploitation1
2026-06-261
Active Exploitation1
2026-06-271
Active Exploitation1
2026-07-031
Disclosure1
2026-07-051
Patch1
2026-07-071
Active Exploitation1
2026-07-0811
Active Exploitation6Disclosure2General1Patch2
2026-07-091
Active Exploitation1
2026-07-103
Active Exploitation1Disclosure1Exploit1
2026-07-121
General1
2026-07-131
Patch1
2026-07-152
Active Exploitation2
2026-07-161
Active Exploitation1
2026-07-201
Disclosure1
2026-07-211
Active Exploitation1
2026-07-237
Active Exploitation6Disclosure1
2026-07-241
Active Exploitation1
2026-08-011
General1
2026-08-271
Disclosure1
Full discourse20 posts
  • Censys@censysio
    Active Exploitation

    🚨 CVE-2026-48908 (CVSS 10.0) A critical flaw in Joomla's SP Page Builder can enable unauthenticated file upload and potential RCE: ▪️Versions 1.0.0–6.6.1 affected ▪️Active exploitation reported ▪️Patched in 6.6.2 Censys observed 194,793 web properties loading the component. Full advisory: https://bit.ly/3QW99gB #CensysARC #CVE202648908

    Post summary

    CVE-2026-48908 in Joomla's SP Page Builder is actively exploited via unauthenticated file upload leading to potential RCE, but a patch (6.6.2) is available to mitigate the issue.

    14521856840.7K
    12.6K followersView on X
  • Yusuf Can Çakır@Yusufcancakiir
    Exploit

    Open directory find. Somebody left the full exploitation toolkit for CVE-2026-48908 (SP Page Builder for Joomla, unauth file upload to RCE, CVSS 10.0) sitting exposed on a single Contabo node in France (AS51167). Operator has been running it since at least 23 June 2026, last activity 2 July. Logs and version-stamped scripts on the box show at least five tool versions and three exploitation batches across that window. Maintained operation, not a one-off scan. The bug. SPPB's asset.uploadCustomIcon task takes a ZIP with no auth and no CSRF token, then extracts it straight into a web-reachable path under the component media dir. Anything in the archive, PHP included, is live over HTTP the moment it lands. Hits every version 1.0.0 through 6.6.1. JoomShaper closed it in 6.6.2 by gating the upload behind admin auth. CISA added it to KEV on 7 July. Campaign flow. Fingerprint sites running SPPB, throw unauthenticated upload attempts in parallel waves, drop a PHP file-manager webshell on whatever takes. Not a minimal backdoor, a standalone file manager: full filesystem access, command execution, upload/download, read on sensitive server files. This operator wants to stay. Result files on the server log hundreds of confirmed shells across academic, government-adjacent, and commercial Joomla sites in several ccTLDs. The bit worth flagging. The shells land through a case-bypass chain, and it is the same one now showing up in the public PoCs for this CVE. The archive filter blocks lowercase .php but does not normalize case, so a mixed-case .PHP passes. Default Apache then serves .PHP as text, so they also drop a .htaccess (which the filter misses too) carrying AddType application/x-httpd-php .PHP to force execution. Practical consequence: a WAF that 403s the JCE wave paths will happily pass this one with a 200. If you patched JCE, wrote a WAF rule, and moved on, you are not covered here. Fix. 6.6.2 or later, that is the only real fix. Then audit the iconfont dir, pull anything unexpected, and if you find a shell assume the host is compromised: rotate every credential on or reachable from that box and walk logs back to 23 June. Stopgap only: block unauth POSTs carrying task=asset.uploadCustomIcon. Attribution. Single Contabo box (AS51167, FR), zero infra diversification, no espionage markers. Reads as opportunistic access collection, brokering or straight monetization of the compromised boxes. Strings and config patterns line up with a Turkish-speaking operator. Hunt for: - iconfont subdirs named ico + six random lowercase letters (icowvmlhh, icofcboxb), with PHP files under fonts/ - webroot dirs named neo_ + four random lowercase letters, e.g. /neo_abcd/fonts/ - PHP under fonts/ with any of .php .PHP .Php .pHp .php3 .php4 .php5 .php7 .pht .phtml .phar - an unexpected .htaccess or .user.ini dropped inside fonts/ next to the PHP - WAF/log signature: unauthenticated POST carrying task=asset.uploadCustomIcon Big thanks to @Huntio.

    Post summary

    The report details the active exploitation of CVE-2026-48908 via a public exploitation toolkit, confirms widespread real‑world use, and provides patch guidance, highlighting that the vulnerability is severe and actively abused.

    29036203.9K
    1.6K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The briefing reports multiple CVEs currently being exploited in the wild, emphasizes patching priority for affected Microsoft, Cisco, Adobe, and other products, and highlights the urgency of addressing active attacks.

    33032123.8K
    125.1K followersView on X
  • ExploitGrid@exploitgrid
    Active Exploitation

    Top CVEs w/ public exploits (Jun 20–27): CVE-2026-48908 Joomla SPB RCE (exploited live) CVE-2026-48909 Joomla SP LMS PHP Obj injection CVE-2026-12417 SignUp/In admin takeover CVE-2026-12416 Invoice Generator takeover CVE-2026-39938 Cacti LFI Protect via http://exploitgrid.net

    Post summary

    The post enumerates several CVEs with publicly available exploits, noting that CVE-2026-48908 is currently being exploited in the wild, but offers no patch or exploit code details.

    2502191.9K
    33 followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Langflow vulnerability CVE-2026-55255, & Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #InfoSec https://t.co/IsmhmuWqlr

    Post summary

    The post announces that three CVEs were added to the KEV catalog and urges readers to apply available mitigations, implying active exploitation in the wild.

    0601717.5K
    302.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-48908 - critical 🚨 Joomla SP Page Builder <= 6.6.1 - Unauthenticated Arbitrary File Upload RCE > SP Page Builder for Joomla contains an unrestricted file upload vulnerability allowin... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-48908 @pdnuclei #Nuclei...

    Post summary

    CVE‑2026‑48908 is a critical unauthenticated arbitrary file upload vulnerability in Joomla SP Page Builder (≤6.6.1) that can lead to remote code execution; no exploitation or patch information is provided in this tweet.

    020127577
    1.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    Here is PoC for CVE-2026-48908: https://github.com/papageo75/CVE-2026-48908-PoC

    Post summary

    The post shares a proof‑of‑concept exploit for CVE‑2026‑48908 via a GitHub repository link.

    0101464.4K
    226.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/7追加) 🛡CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 SP Page Builder に存在する、危険なタイプのファイルの無制限アップロードの脆弱性です。 未認証の攻撃者が任意ファイルをアップロードし、最終的に PHP コードのアップロードおよび実行につなげられる可能性があります。 影響を受けるバージョンは SP Page Builder 1.0.0 から 6.6.1 までであり、6.6.2 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで SP Page Builder を使用している ・SP Page Builder 1.0.0 から 6.6.1 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・SP Page Builder 6.6.2 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意ファイルをアップロードされる可能性がある ・PHP ファイルを Web ルート配下に配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・不正な Super Administrator アカウントやバックドアを設置される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(mySites .guru) ・概要:mySites .guru は、SP Page Builder の asset.uploadCustomIcon タスクが認証チェックおよびサーバー側のファイル種別制限なしにアップロードを処理し、.php ファイルの配置と実行につながることを確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-48908 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/48xxx/CVE-2026-48908.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 ・https://www.joomshaper.com/page-builder ・https://www.joomshaper.com/forum/question/45152 ・https://extensions.joomla.org/extension/sp-page-builder/ ・https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html 🛡CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability ✅概要 ・深刻度:重要 8.4 (CVSS Base) / GitHub, Inc. (CNA) ・種別:ユーザ制御の鍵による認証回避 (CWE-639) ・CVSS:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L Langflow の /api/v1/responses エンドポイントに存在する IDOR の脆弱性です。 認証済みの攻撃者が、被害者の flow ID をリクエスト内で指定することで、別ユーザーに属する任意の flow を実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Langflow 1.9.1 未満を使用している ・攻撃者が対象 Langflow 環境へネットワーク経由でアクセスできる ・攻撃者が Langflow 上で認証済みである ・攻撃者が被害者の flow ID を取得または推測以外の手段で入手できる ・Langflow 1.9.1 以降へ更新されていない ✅悪用時影響 ・別ユーザーに属する flow を実行される可能性がある ・被害者 flow の実行コンテキストで機密情報や API キーの漏えいにつながる可能性がある ・マルチテナント環境でテナント境界を越えた不正操作につながる可能性がある ・Langflow 上の AI ワークフローや外部連携先の認証情報を悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Sysdig Threat Research Team) ・概要:Sysdig Threat Research Team は、事例を確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-55255 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/55xxx/CVE-2026-55255.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255 ・https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ・https://github.com/langflow-ai/langflow/pull/12832 ・https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e ・https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited ・https://jvndb.jvn.jp/ja/cwe/CWE-639.html 🛡CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 Page Builder CK に存在する、未認証の任意ファイルアップロードの脆弱性です。 攻撃者が認証なしで実行可能ファイルをアップロードし、リモートコード実行につなげられる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで Page Builder CK を使用している ・Page Builder CK 1.0 から 3.6.0 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意ファイルをアップロードされる可能性がある ・実行可能ファイルを任意の配置先に設置される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェルやバックドアを設置される可能性がある ・サイトの改ざん、情報窃取、追加侵害に利用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(mySites .guru) ・概要:mySites .guru は、Page Builder CK において認証なしで任意ファイルアップロードが可能であり、攻撃者が配置先フォルダを選択できるため、実行可能ファイルを配置して RCE につなげられると説明。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-56290 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/56xxx/CVE-2026-56290.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290 ・https://www.joomlack.fr/ ・https://www.joomlack.fr/en/joomla-extensions/page-builder-ck ・https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3 ・https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post lists three critical CVEs added to CISA’s catalog, confirms in‑the‑wild exploitation, provides partial PoC references, and notes vendor‑issued patches.

    001727.3K
    44.2K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni #Zafiyet: JoomShaper SP Page Builder - Yetkisiz Dosya Yükleme (Unrestricted File Upload) CVE Kodu: CVE-2026-48908 Zafiyet Türü: Tehlikeli Türde Dosyanın Kısıtlamasız Yüklenebilmesi (CWE-434) Fidye Yazılımı (Ransomware) Faaliyeti: Bilinmiyor 📌 Zafiyetin Özeti #JoomShaper SP Page Builder üzerinde, tehlikeli dosya türlerinin yüklenmesini kısıtlamayan kritik bir zafiyet tespit edilmiştir. Bu güvenlik açığı, kimliği doğrulanmamış (unauthenticated) kullanıcıların sisteme rastgele dosyalar yüklemesine ve nihayetinde sunucu üzerinde zararlı PHP kodlarının çalıştırılmasına olanak tanımaktadır. 🛠️ Alınması Gereken Aksiyonlar 👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın. 👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin. 👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz dosya yüklemelerini engellemek için gerekli sıkılaştırmaları yapın. 👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.

    Post summary

    The bulletin reports an unrestricted file‑upload flaw (CVE‑2026‑48908) in JoomShaper SP Page Builder that lets unauthenticated users upload arbitrary PHP code, and it urges applying vendor‑released patches and mitigations.

    02070175
    530 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2025-32432 CVE-2025-57819 CVE-2026-48908 CVE-2026-76460 CVE-2026-85706 ..🧵👇

    2102082
    42 followersView on X
  • CAIS/RNP@caisRNP
    Disclosure

    O CAIS alerta a comunidade de segurança cibernética sobre a CVE-2026-48908 no SP Page Builder para Joomla, que permite execução remota de código. Mais informações: https://bit.ly/4weWtAI

    Post summary

    CAIS has alerted the cybersecurity community about CVE-2026-48908, a remote code execution vulnerability in SP Page Builder for Joomla, providing a link for additional details.

    01030290
    2.4K followersView on X
  • EcuCERT@EcuCERT_EC
    Active Exploitation

    Se detectó una campaña de Defacement que explota las vulnerabilidades CVE-2026-48907, CVE-2026-48908 y CVE-2026-49049 en Joomla!, dirigida a portales institucionales de Ecuador. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/07/Al-2026-037-Campana-de-Defacement-en-Portales-Institucionales-Basados-en-Joomla-en-Ecuador.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/hvVTFt35KM

    Post summary

    A defacement campaign in Ecuador targeting Joomla! sites has been detected, actively exploiting CVE-2026-48907, CVE-2026-48908, and CVE-2026-49049.

    02010295
    2.0K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    📍 Ivanti Sentry CVE-2026-10520 📍 Check Point VPN CVE-2026-50751 📍 Joomla SP Page Builder CVE-2026-48908 Package اسمها skytext وصلت تقريباً 2,400 تحميل، أغلبها على Linux. https://t.co/1oEsyNaiDW

    Post summary

    The tweet simply enumerates a few newly disclosed CVEs without providing details on PoCs, exploits, patches, or technical specifics.

    10020436
    49.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-48908: 🚨 CVE-2026-48908 (CVSS 10.0) A critical flaw in Joomla's SP Page Builder can enable unauthenticated file upload and potential RCE: ▪️Versions 1.0.0–6.6.1 affected ▪️Active exploitation reported ▪️Patched in 6.6.2 Censys observed 194,793 web properties…

    Post summary

    The text announces a critical Joomla SP Page Builder flaw with a CVSS of 10.0, notes active exploitation in the wild, specifies a patch release, and provides detailed technical information.

    1001038
    321 followersView on X
  • dbugs@ptdbugs
    PoC

    Joomla Extension - http://joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 CVE: CVE-2026-48908 PT ID: PT-2026-51135 Vendor: Joomla (http://joomshaper.net) Product: SP Page Builder extension for Joomla CVSS: 10 Credits: Phil Taylor Description: A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-48908 • https://www.joomshaper.com/page-builder PoC/Exploit: https://github.com/papageo75/CVE-2026-48908-PoC #dbugs_vuln

    Post summary

    The post announces a critical RCE vulnerability in SP PageBuilder and shares a proof‑of‑concept exploit on GitHub, but does not report active exploitation or a vendor patch.

    00020432
    3.0K followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-48908 [CRITICAL/PoC] CVE-2026-48908 🔗 https://exploitgrid.net/exploits/069aaecf-01e9-42f6-b17a-6bbd5e309f58

    1000046
    42 followersView on X
  • ASPL hosting@ASPLhosting
    Active Exploitation

    En esta tanda cubrimos tres vectores de explotación activa: - wp2shell (CVE-2026-63030 y CVE-2026-60137, WordPress core): /wp-json/batch/v1 y parámetros REST - SP Page Builder (CVE-2026-48908): tarea asset.uploadCustomIcon - Helix3 (CVE-2026-49049): manejador AJAX com_ajax

    Post summary

    The post reports three CVEs with active exploitation vectors, detailing specific API endpoints and AJAX handlers used, but does not provide PoC code, exploits, patches, or debunking statements.

    10000145
    129 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. CVE-2026-48908 added to CISA KEV: JoomShaper SP Page Builder

    Post summary

    CVE-2026-48908, affecting JoomShaper SP Page Builder, has been added to the CISA KEV list and witnessed its first exploitation attempt in the wild.

    1000046
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. CVE-2026-48908 added to CISA KEV: JoomShaper SP Page Builder

    Post summary

    The brief tweet states that CVE-2026-48908 for JoomShaper SP Page Builder has been added to the CISA KEV list, implying it is recognized as an actively exploited vulnerability.

    1000036
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. CVE-2026-48908 added to CISA KEV: JoomShaper SP Page Builder

    Post summary

    CVE-2026-48908, affecting JoomShaper SP Page Builder, was flagged by Lyrie Sentinel and subsequently added to the CISA KEV list, indicating that the vulnerability is being actively exploited in the wild.

    1000035
    326 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appollyosp_page_builder-joomla\!-

Explore more