CVE-2026-48939Active Exploitation(joomlic / icagenda)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch joomlic icagenda systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-13. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • icagenda

Threat summary

  • Active exploitation appears in 30 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 57 mentions across 19 observed days

What's happening

  • Active exploitation reported across 30 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 41 signals
  • Disclosure: 12 classified signals
  • General: 8 classified signals
  • Peaked 10d ago at 11 mentions (2026-07-13); latest day: 5
  • 57 total mentions across 19 days

Affected systems

Vendors
Products
icagenda

Deep dive

Activity timeline57 mentions / 19d
036811Mentions · 2026-06-20: 2Mentions · 2026-06-21: 1Mentions · 2026-06-25: 1Mentions · 2026-07-05: 1Mentions · 2026-07-06: 2Mentions · 2026-07-10: 2Mentions · 2026-07-11: 6Mentions · 2026-07-12: 2Mentions · 2026-07-13: 11Mentions · 2026-07-14: 3Mentions · 2026-07-15: 2Mentions · 2026-07-16: 3Mentions · 2026-07-20: 1Mentions · 2026-07-21: 1Mentions · 2026-07-23: 10Mentions · 2026-07-27: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 2Mentions · 2026-08-19: 5PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-23: 5PoC Mentioned / Linked · 2026-08-06: 1Exploit Tool / Code · 2026-07-06: 1Exploit Tool / Code · 2026-07-13: 1Exploit Tool / Code · 2026-07-23: 2Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-11: 4Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-13: 7Active Exploitation · 2026-07-14: 3Active Exploitation · 2026-07-15: 2Active Exploitation · 2026-07-16: 3Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-07-23: 2Active Exploitation · 2026-07-27: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-13: 5Patch / Workaround · 2026-07-14: 2Patch / Workaround · 2026-07-16: 2Patch / Workaround · 2026-08-05: 1Technical Details · 2026-06-20: 2Technical Details · 2026-06-21: 1Technical Details · 2026-06-25: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-10: 1Technical Details · 2026-07-11: 4Technical Details · 2026-07-12: 2Technical Details · 2026-07-13: 10Technical Details · 2026-07-14: 2Technical Details · 2026-07-15: 2Technical Details · 2026-07-16: 2Technical Details · 2026-07-20: 1Technical Details · 2026-07-21: 1Technical Details · 2026-07-23: 4Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-19: 306-2006-2106-2507-0507-0607-1007-1107-1207-1307-1407-1507-1607-2007-2107-2307-2708-0508-0608-19
Signal classification5 categories
Active Exploitation
2849.1%
Disclosure
1221.1%
General
814.0%
PoC
58.8%
Patch
47.0%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-202
Active Exploitation1General1
2026-06-211
Disclosure1
2026-06-251
Active Exploitation1
2026-07-051
Patch1
2026-07-062
Disclosure1PoC1
2026-07-102
Active Exploitation1Disclosure1
2026-07-116
Active Exploitation4Disclosure1General1
2026-07-122
Active Exploitation1General1
2026-07-1311
Active Exploitation6Disclosure1General2Patch2
2026-07-143
Active Exploitation2Patch1
2026-07-152
Active Exploitation2
2026-07-163
Active Exploitation3
2026-07-201
Active Exploitation1
2026-07-211
Active Exploitation1
2026-07-2310
Active Exploitation2Disclosure3General1PoC4
2026-07-271
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-062
Disclosure2
2026-08-195
Active Exploitation1Disclosure2General2
Full discourse20 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-48939 PT ID: PT-2026-51137 Vendor: Joomla Product: iCagenda (extension for Joomla) Description: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. Link: https://github.com/shinthink/CVE-2026-48939 #dbugs_vuln

    Post summary

    A PoC and exploit for CVE-2026-48939, enabling arbitrary file upload and PHP code execution in Joomla’s iCagenda extension, has been made publicly available on GitHub.

    05035118.2K
    3.4K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The briefing highlights multiple actively exploited CVEs, stresses immediate patching, and warns of ongoing exploitation, especially for Microsoft and Cisco IOS vulnerabilities.

    33032123.8K
    125.1K followersView on X
  • YogSotho@YogSoth0
    Disclosure

    🩸 #CVE-2026-48939 — iCagenda #Joomla #RCE #Exploit kit Overview ⚠️ Pre-authentication Remote Code Execution in iCagenda Joomla Extension via arbitrary file upload. 🚨 CVSS 10.0 - Affects all versions prior to: - v3.9.15 (for 3.x branch) - v4.0.8 (for 4.x branch) #0days #security #hacking #cybersecurity #cybernews #antisec #infosec #CVSS #vulnerability #icagenda #proxy #shell #python

    Post summary

    The post discloses a critical remote‑code‑execution flaw in iCagenda Joomla, detailing its mechanism, severity, and affected versions but provides no exploit code or evidence of active attacks.

    0302641.6K
    1.9K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added iCagenda vulnerability CVE-2026-48939 & Balbooa Forms vulnerability CVE-2026-56291 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/R2FueU753j

    Post summary

    The tweet informs that CVE‑2026‑48939 and CVE‑2026‑56291 have been added to the DHS KEV Catalog and urges organizations to apply mitigations to defend against ongoing exploitation.

    3801728.2K
    302.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-48939 - critical 🚨 Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE > iCagenda extension for Joomla contains an unrestricted file upload vulnerability in t... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-48939 @pdnuclei #NucleiTemplat...

    Post summary

    A critical unauthenticated RCE in Joomla iCagenda <3.9.10 has been disclosed, with a link pointing to a PoC. No evidence of active exploitation or patch status is provided.

    0001771.1K
    1.3K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 Two Critical Joomla Flaws Exploited as Zero-Days CISA has added two maximum-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: ⚠️ CVE-2026-48939: iCagenda arbitrary file upload ⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote code execution Both flaws carry a CVSS score of 10.0 Attackers can upload malicious PHP files and deploy web shells Affected users should immediately update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1, then inspect their Joomla environments for suspicious PHP files and unauthorized administrator accounts. Analyst Note: Installing the patch does not remove an existing compromise. Organizations must perform a full integrity review, rotate credentials, and investigate historical access logs. #DDW #Intelligence #DarkWeb #Joomla

    Post summary

    The text reports that two Joomla vulnerabilities are actively exploited, provides exploit details and CVSS scores, and lists patches to remediate.

    0301747.4K
    202.1K followersView on X
  • watchTowr@watchtowrcyber
    General

    Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critical Remote Code Execution vulnerability in iCagenda extension for Joomla to KEV, watchTowr clients were aware of their exposure. Reach out via our website if you need support. https://t.co/WtwnCrQTS5

    Post summary

    The text announces that watchTowr clients were warned about a critical RCE flaw in the iCagenda Joomla extension 10 days before CISA listed it in KEV, but it offers no exploit code, patch, or evidence of active attacks.

    0301002.4K
    12.6K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/10追加) 🛡CVE-2026-48939 ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 iCagenda extension に存在する、危険なタイプのファイルをアップロードできる脆弱性です。 ファイル添付機能を通じて任意ファイルをアップロードでき、最終的に PHP コードのアップロードおよび実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月13日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで iCagenda extension を使用している ・iCagenda 3.2.1 から 3.9.14、または 4.0.0 から 4.0.7 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・Joomla 6 環境では PHP Web シェルのアップロードおよび実行につながる可能性がある ・iCagenda 3.9.15 または 4.0.8 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者にファイル添付機能を悪用される可能性がある ・PHP ファイルを Web ルート配下の添付ファイル保存先へ配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェル、バックドア設置、サイト改ざん、情報窃取に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(http://mySites.guru / JoomliC) ・概要:http://mySites.guru は、icagenda-batch/1.0 を名乗る自動化された攻撃により、公開フォームから悪意あるファイルがアップロードされ、その後 iCagenda の添付ファイル保存先に配置された PHP ファイルへアクセスする一連の悪用を確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-48939 ・https://www.icagenda.com/ ・https://www.icagenda.com/docs/changelog/icagenda-3-9-15 ・https://www.icagenda.com/docs/changelog/icagenda-4-0-8 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/48xxx/CVE-2026-48939.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 ・https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ ・https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html 🛡CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 Balbooa Forms に存在する、危険なタイプのファイルをアップロードできる脆弱性です。 未認証の攻撃者が実行可能ファイルをアップロードし、フルリモートコード実行につなげられる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月13日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで Balbooa Forms を使用している ・Balbooa Forms 1.0 から 2.4.0 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・公開フォームの添付ファイルアップロード処理が到達可能である ・Balbooa Forms 2.4.1 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者にファイルアップロード機能を悪用される可能性がある ・PHP ファイルを Web ルート配下のアップロードディレクトリへ配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェル、バックドア、不正な管理者アカウント設置、情報窃取に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(http://mySites.guru) ・概要:http://mySites.guru は、Hetzner の abuse report を契機に実環境のアクセスログを確認し、Balbooa Forms のアップロードハンドラに対する POST リクエストが悪用されていたこと、またローカルの Joomla 環境で未認証アップロードから RCE に至る一連の挙動を再現したことを公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-56291 ・https://www.balbooa.com/joomla-forms ・https://github.com/cisagov/vulnrichment/blob/develop/2026/56xxx/CVE-2026-56291.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56291 ・https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed that two Joomla extensions are being actively exploited via unrestricted file upload, with publicly available PoC/exploit code and explicit patch releases available.

    000636.7K
    44.2K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz #Zafiyet: #iCagenda - Yetkisiz Dosya Yükleme (Unrestricted File Upload) CVE Kodu: CVE-2026-48939 Zafiyet Türü: Tehlikeli Türde Dosyanın Kısıtlamasız Yüklenebilmesi (CWE-434) Fidye Yazılımı (#Ransomware) Faaliyeti: Bilinmiyor 📌 Zafiyetin Özeti iCagenda üzerinde, tehlikeli dosya türlerinin yüklenmesini kısıtlamayan kritik bir zafiyet tespit edilmiştir. Bu güvenlik açığı, dosya eki (file attachment) özelliği üzerinden sisteme rastgele dosyaların yüklenmesine olanak tanımakta ve nihayetinde sunucu üzerinde zararlı PHP kodlarının yüklenip çalıştırılmasına (code execution) yol açabilmektedir. 🛠️ Alınması Gereken Aksiyonlar 👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın. 👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin. 👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz dosya yüklemelerini engellemek için gerekli yapılandırmaları sağlayın. 👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.

    Post summary

    CVE‑2026‑48939 is an unrestricted file‑upload flaw (CWE‑434) in iCagenda that can enable arbitrary PHP code execution; the bulletin urges immediate patching or mitigation.

    0103019
    530 followersView on X
  • PCMedicalist@PCMedicalist
    General

    🟦 PCMedicalist Signal · Jul 13 • Misconfigured Server Reveals Three Evilginx Phishing Opera… — The Hacker News • iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploit… CVE-2026-48939 — The Hacker News #SecurityNews #Python SecOps · Blue Team · Autonomous Builds https://t.co/6HxIF9D7CS

    Post summary

    The tweet references CVE‑2026‑48939 but offers no substantive technical, exploit, or patch information, resulting in a very general categorization.

    0102085
    153 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Two Joomla CISA KEV zero-days, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), both CVSS 10.0, enable unauthenticated PHP file upload and RCE. #DFIR_Radar https://t.co/wxvHUTXVCQ

    Post summary

    The tweet discloses two critical Joomla zero‑day CVEs with high severity (CVSS 10.0) and details the vulnerability type—unauthenticated PHP file upload leading to RCE—without providing exploit code, patch updates, or evidence of active exploitation.

    10010177
    1.8K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for vulnerability critical 2026 Posted: 2026-07-13T11:08:21.000Z Likes: 10 0day Intel: Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critic

    Post summary

    A brief tweet indicates that an analyst had identified CVE-2026-48939 roughly ten days before CISA released an official notice, but offers no further details, exploit evidence, or remediation advice.

    1000031
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    0day Intel: Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critic

    Post summary

    The post only references the CVE identifier and its timing relative to a CISA announcement, offering no technical, exploit, or mitigation details.

    1000027
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Full Tweet Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critical Remote Code Execution vulnerability in iCagenda extension for Joomla to KEV, watchTowr clients were aware of their exposure.

    Post summary

    The tweet notes that watchTowr clients were aware of CVE‑2026‑48939 – a critical RCE in iCagenda – before CISA added it to KEV, underscoring proactive monitoring.

    1000041
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-48939: Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critical Remote Code Execution vulnerability in iCagenda extension for Joomla to KEV, watchTowr clients were aware of their exposure. Reach out via our website if you need support.…

    Post summary

    The post discloses CVE‑2026‑48939, a critical RCE in the iCagenda Joomla extension, noting early client exposure but providing no PoC or exploitation details.

    1000053
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-48939: 🚨 Two Critical Joomla Flaws Exploited as Zero-Days CISA has added two maximum-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: ⚠️ CVE-2026-48939: iCagenda arbitrary file upload ⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote…

    Post summary

    CISA has cataloged CVE-2026-48939 and CVE-2026-56291 as actively exploited Joomla zero‑day vulnerabilities, with the former allowing arbitrary file upload.

    1000038
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    11:50 UTC: First exploit attempt in the wild. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939

    Post summary

    Report claims the first real‑world exploitation attempt for CVE‑2026‑48939, with a PoC discovered but no detailed exploit code or mitigation information provided.

    1000055
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    09:01 UTC: GPT-5 enrichment complete. 70 words. 1 citations. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939

    Post summary

    The message announces that a PoC/exploit has been discovered for CVE‑2026‑48939, but offers no technical or exploitation details or evidence of active attacks.

    1000047
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    08:53 UTC: Lyrie Sentinel flagged it. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑48939 has been discovered, but no further technical details, patch information, or evidence of active exploitation are included.

    1000043
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    09:04 UTC: Thread live on @lyrie_ai. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939

    Post summary

    A PoC/exploit has been discovered for CVE-2026-48939, but no additional technical details or active exploitation reports are provided.

    1000052
    326 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlicicagenda-joomla\!-

Explore more