Exploitation observed; activity peaked at 11 mentions and remains active
Immediate actions
Patch joomlic icagenda systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-13. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A PoC/exploit has been discovered for vulnerability CVE-2026-48939
PT ID: PT-2026-51137
Vendor: Joomla
Product: iCagenda (extension for Joomla)
Description: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Link: https://github.com/shinthink/CVE-2026-48939
#dbugs_vuln
Post summary
A PoC and exploit for CVE-2026-48939, enabling arbitrary file upload and PHP code execution in Joomla’s iCagenda extension, has been made publicly available on GitHub.
Daniel's Daily Threat Intel & CVE Briefing (from claude)
Tue 15 Jul 2026
Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today.
1. CISA KEV / Actively Exploited (lead)
CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media)
CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI)
CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer)
Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek)
2. Edge / Network Gear
Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle.
3. Microsoft / Windows / Active Directory
Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI)
CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first.
CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately.
CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models.
So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog.
4. Web / Cloud / DevOps
Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com)
Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI)
No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise.
Watch / developing
Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days.
Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched.
Sources:
CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs)
ZDI — July 2026 Security Update Review
BleepingComputer — July 2026 Patch Tuesday, 3 zero-days
Tenable — July 2026 Patch Tuesday analysis
The Hacker News — Adobe/Joomla/Langflow KEV additions
SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla
http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR
SC Media — CISA adds Cisco IOS flaw to KEV
Post summary
The briefing highlights multiple actively exploited CVEs, stresses immediate patching, and warns of ongoing exploitation, especially for Microsoft and Cisco IOS vulnerabilities.
🩸 #CVE-2026-48939 — iCagenda #Joomla#RCE#Exploit kit
Overview
⚠️ Pre-authentication Remote Code Execution in iCagenda Joomla Extension via arbitrary file upload.
🚨 CVSS 10.0 - Affects all versions prior to:
- v3.9.15 (for 3.x branch)
- v4.0.8 (for 4.x branch)
#0days#security#hacking#cybersecurity#cybernews#antisec#infosec#CVSS#vulnerability#icagenda#proxy#shell#python
Post summary
The post discloses a critical remote‑code‑execution flaw in iCagenda Joomla, detailing its mechanism, severity, and affected versions but provides no exploit code or evidence of active attacks.
🛡️ We added iCagenda vulnerability CVE-2026-48939 & Balbooa Forms vulnerability CVE-2026-56291 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/R2FueU753j
Post summary
The tweet informs that CVE‑2026‑48939 and CVE‑2026‑56291 have been added to the DHS KEV Catalog and urges organizations to apply mitigations to defend against ongoing exploitation.
A critical unauthenticated RCE in Joomla iCagenda <3.9.10 has been disclosed, with a link pointing to a PoC. No evidence of active exploitation or patch status is provided.
🚨 Two Critical Joomla Flaws Exploited as Zero-Days
CISA has added two maximum-severity vulnerabilities to its Known Exploited Vulnerabilities catalog:
⚠️ CVE-2026-48939: iCagenda arbitrary file upload
⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote code execution
Both flaws carry a CVSS score of 10.0
Attackers can upload malicious PHP files and deploy web shells
Affected users should immediately update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1, then inspect their Joomla environments for suspicious PHP files and unauthorized administrator accounts.
Analyst Note: Installing the patch does not remove an existing compromise. Organizations must perform a full integrity review, rotate credentials, and investigate historical access logs.
#DDW#Intelligence#DarkWeb#Joomla
Post summary
The text reports that two Joomla vulnerabilities are actively exploited, provides exploit details and CVSS scores, and lists patches to remediate.
Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critical Remote Code Execution vulnerability in iCagenda extension for Joomla to KEV, watchTowr clients were aware of their exposure.
Reach out via our website if you need support. https://t.co/WtwnCrQTS5
Post summary
The text announces that watchTowr clients were warned about a critical RCE flaw in the iCagenda Joomla extension 10 days before CISA listed it in KEV, but it offers no exploit code, patch, or evidence of active attacks.
CISA confirmed that two Joomla extensions are being actively exploited via unrestricted file upload, with publicly available PoC/exploit code and explicit patch releases available.
🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik#GüvenlikBülteni
Merhaba #Brolyz#Zafiyet: #iCagenda - Yetkisiz Dosya Yükleme (Unrestricted File Upload)
CVE Kodu: CVE-2026-48939
Zafiyet Türü: Tehlikeli Türde Dosyanın Kısıtlamasız Yüklenebilmesi (CWE-434)
Fidye Yazılımı (#Ransomware) Faaliyeti: Bilinmiyor
📌 Zafiyetin Özeti
iCagenda üzerinde, tehlikeli dosya türlerinin yüklenmesini kısıtlamayan kritik bir zafiyet tespit edilmiştir. Bu güvenlik açığı, dosya eki (file attachment) özelliği üzerinden sisteme rastgele dosyaların yüklenmesine olanak tanımakta ve nihayetinde sunucu üzerinde zararlı PHP kodlarının yüklenip çalıştırılmasına (code execution) yol açabilmektedir.
🛠️ Alınması Gereken Aksiyonlar
👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın.
👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin.
👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz dosya yüklemelerini engellemek için gerekli yapılandırmaları sağlayın.
👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.
Post summary
CVE‑2026‑48939 is an unrestricted file‑upload flaw (CWE‑434) in iCagenda that can enable arbitrary PHP code execution; the bulletin urges immediate patching or mitigation.
🟦 PCMedicalist Signal · Jul 13
• Misconfigured Server Reveals Three Evilginx Phishing Opera… — The Hacker News
• iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploit… CVE-2026-48939 — The Hacker News
#SecurityNews#Python
SecOps · Blue Team · Autonomous Builds https://t.co/6HxIF9D7CS
Post summary
The tweet references CVE‑2026‑48939 but offers no substantive technical, exploit, or patch information, resulting in a very general categorization.
Two Joomla CISA KEV zero-days, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), both CVSS 10.0, enable unauthenticated PHP file upload and RCE.
#DFIR_Radar https://t.co/wxvHUTXVCQ
Post summary
The tweet discloses two critical Joomla zero‑day CVEs with high severity (CVSS 10.0) and details the vulnerability type—unauthenticated PHP file upload leading to RCE—without providing exploit code, patch updates, or evidence of active exploitation.
Source: X search for vulnerability critical 2026
Posted: 2026-07-13T11:08:21.000Z
Likes: 10
0day Intel: Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critic
Post summary
A brief tweet indicates that an analyst had identified CVE-2026-48939 roughly ten days before CISA released an official notice, but offers no further details, exploit evidence, or remediation advice.
Full Tweet
Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critical Remote Code Execution vulnerability in iCagenda extension for Joomla to KEV, watchTowr clients were aware of their exposure.
Post summary
The tweet notes that watchTowr clients were aware of CVE‑2026‑48939 – a critical RCE in iCagenda – before CISA added it to KEV, underscoring proactive monitoring.
CVE-2026-48939: Rapid reaction gets you ahead. 10 days before CISA added CVE-2026-48939 a critical Remote Code Execution vulnerability in iCagenda extension for Joomla to KEV, watchTowr clients were aware of their exposure. Reach out via our website if you need support.…
Post summary
The post discloses CVE‑2026‑48939, a critical RCE in the iCagenda Joomla extension, noting early client exposure but providing no PoC or exploitation details.
CVE-2026-48939: 🚨 Two Critical Joomla Flaws Exploited as Zero-Days CISA has added two maximum-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: ⚠️ CVE-2026-48939: iCagenda arbitrary file upload ⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote…
Post summary
CISA has cataloged CVE-2026-48939 and CVE-2026-56291 as actively exploited Joomla zero‑day vulnerabilities, with the former allowing arbitrary file upload.
11:50 UTC: First exploit attempt in the wild.
0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939
Post summary
Report claims the first real‑world exploitation attempt for CVE‑2026‑48939, with a PoC discovered but no detailed exploit code or mitigation information provided.
09:01 UTC: GPT-5 enrichment complete. 70 words. 1 citations.
0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939
Post summary
The message announces that a PoC/exploit has been discovered for CVE‑2026‑48939, but offers no technical or exploitation details or evidence of active attacks.
08:53 UTC: Lyrie Sentinel flagged it.
0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-48939
Post summary
A proof‑of‑concept/exploit for CVE‑2026‑48939 has been discovered, but no further technical details, patch information, or evidence of active exploitation are included.