CVE-2026-48909Disclosure

HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

7.8/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 2 mentions (2026-06-21); latest day: 1
  • 10 total mentions across 8 days

Deep dive

Activity timeline10 mentions / 8d
01122Mentions · 2026-06-20: 1Mentions · 2026-06-21: 2Mentions · 2026-06-22: 2Mentions · 2026-06-23: 1Mentions · 2026-06-27: 1Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Mentions · 2026-07-23: 1PoC Mentioned / Linked · 2026-06-22: 2PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-07-06: 1Exploit Tool / Code · 2026-06-22: 2Exploit Tool / Code · 2026-06-23: 1Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-21: 1Technical Details · 2026-06-22: 2Technical Details · 2026-06-23: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-23: 106-2006-2106-2206-2306-2707-0607-0707-23
Signal classification6 categories
Disclosure
330.0%
PoC
330.0%
General
110.0%
Active Exploitation
110.0%
Exploit
110.0%
Patch
110.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-06-201
General1
2026-06-212
Active Exploitation1Disclosure1
2026-06-222
PoC2
2026-06-231
PoC1
2026-06-271
Exploit1
2026-07-061
Patch1
2026-07-071
Disclosure1
2026-07-231
Disclosure1
Full discourse10 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-48909: SP LMS PHP Object Injection to RCE CVSS: 9.5 Published: June 21st, 2026 PoC: https://github.com/Is4yev/CVE-2026-48909 https://t.co/tkZ1brhcsL

    Post summary

    The tweet announces CVE-2026-48909 with a high CVSS score, provides a direct PoC link that demonstrates RCE, but offers no evidence of active exploitation or remediation steps.

    261124113032.7K
    226.8K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    Top CVEs w/ public exploits (Jun 20–27): CVE-2026-48908 Joomla SPB RCE (exploited live) CVE-2026-48909 Joomla SP LMS PHP Obj injection CVE-2026-12417 SignUp/In admin takeover CVE-2026-12416 Invoice Generator takeover CVE-2026-39938 Cacti LFI Protect via http://exploitgrid.net

    Post summary

    The post catalogs several CVEs with publicly available exploits, noting that at least one is actively being used in the wild, but offers no patch or mitigation information.

    2502191.9K
    33 followersView on X
  • Clandestine@akaclandestine
    PoC

    https://github.com/Is4yev/CVE-2026-48909

    Post summary

    The GitHub repository hosts a proof‑of‑concept exploit for CVE‑2026‑48909, detailing the vulnerability and providing execution code, but it does not indicate active exploitation or mention patches.

    02022123.2K
    63.3K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-48909 - critical 🚨 Joomla SP LMS <= 4.1.3 - Remote Code Execution > SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data wit... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-48909 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑48909, a critical remote code execution flaw affecting Joomla SP LMS versions 4.1.3 and earlier, and directs readers to a ProjectDiscovery library page for further details.

    02012296
    1.1K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    Joomla SP LMS PHP object injection (CVE-2026-48909) allows RCE via lmsOrders cookie. Update to 4.1.4 or Joomla 5.2.2 to mitigate. For More: https://www.redsecuretech.co.uk/blog/post/joomla-sp-lms-php-object-injection-leads-to-rce/1306 #Joomla #SPLMS #PHPObjectInjection #CVE202648909 #Unserialize #Webshell #RCE #InfoSec #CyberSecurity https://t.co/B5v4FrwkX8

    Post summary

    The post warns of a Joomla SP LMS PHP object injection flaw (CVE-2026-48909) that allows RCE via the lmsOrders cookie and recommends updating to version 4.1.4 or Joomla 5.2.2 for remediation.

    0101073
    69 followersView on X
  • dbugs@ptdbugs
    PoC

    Joomla Extension - http://joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4 CVE: CVE-2026-48909 PT ID: PT-2026-51136 Vendor: Joomla (http://joomshaper.net) Product: SP LMS extension for Joomla CVSS: 9.5 Credits: Amin Isayev Description: SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-48909 • https://www.joomshaper.com/ PoC/Exploit: https://github.com/Is4yev/CVE-2026-48909 #dbugs_vuln

    Post summary

    An active proof‑of‑concept exploit for CVE‑2026‑48909 targeting the SP LMS Joomla extension is publicly available, confirming its vulnerability to remote code execution via object injection.

    00011408
    1.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-48909 is a PHP object injection in JoomShaper SP LMS &lt;= 4.1.3 via the lmsOrders cookie, triggering FormattedtextLogger.__destruct() to write a webshell. On Joomla &lt; 5.2.2, this achieves RCE. #DFIR_Radar https://t.co/7uES7ycuuv

    Post summary

    The post announces the discovery of CVE-2026-48909, detailing how a PHP object injection in JoomShaper SP LMS allows webshell creation and RCE on Joomla sites.

    10000175
    1.7K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting http://joomshaper.net SP LMS Extension (CVE-2026-48909) https://vuldb.com/vuln/372540/cti

    Post summary

    The CTI team reports multiple activities targeting CVE‑2026‑48909, indicating active exploitation, but provides no technical details, PoC, or mitigation information.

    0100069
    2.2K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-48909 (CVSS 9.5): SP LMS by JoomShaper &lt; 4.1.4 allows unauthenticated remote code execution. Review and update affected Joomla sites promptly. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/1ZMu2XQWAe

    Post summary

    The tweet announces CVE-2026-48909, a high‑severity RCE vulnerability affecting SP LMS on Joomla prior to 4.1.4, and urges sites to apply updates promptly.

    0100071
    93 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-48909 Unauthenticated Remote Code Execution in SP LMS Below 4.1.4 via Deserialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48909

    Post summary

    A CVE for SP LMS is disclosed, indicating unauthenticated RCE through deserialization in versions under 4.1.4, but no PoC, exploit, patch, or active exploitation details are provided.

    0100048
    4.1K followersView on X

Explore more