CVE-2026-56290Active Exploitation(joomlack / page_builder_ck)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch joomlack page_builder_ck systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • page_builder_ck

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 38 mentions across 16 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 25 signals
  • Disclosure: 8 classified signals
  • Peaked 9d ago at 9 mentions (2026-07-08); latest day: 2
  • 38 total mentions across 16 days

Affected systems

Vendors
Products
page_builder_ck

Deep dive

Activity timeline38 mentions / 16d
02579Mentions · 2026-06-29: 4Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-05: 2Mentions · 2026-07-07: 1Mentions · 2026-07-08: 9Mentions · 2026-07-12: 1Mentions · 2026-07-13: 2Mentions · 2026-07-16: 1Mentions · 2026-07-19: 3Mentions · 2026-07-21: 2Mentions · 2026-07-22: 4Mentions · 2026-07-23: 3Mentions · 2026-08-01: 1Mentions · 2026-09-06: 2PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-19: 1PoC Mentioned / Linked · 2026-07-22: 4PoC Mentioned / Linked · 2026-09-06: 1Exploit Tool / Code · 2026-06-29: 1Exploit Tool / Code · 2026-07-05: 1Exploit Tool / Code · 2026-07-19: 1Exploit Tool / Code · 2026-07-22: 1Exploit Tool / Code · 2026-09-06: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 6Active Exploitation · 2026-07-13: 2Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-23: 2Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 4Patch / Workaround · 2026-07-13: 2Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-07-23: 2Technical Details · 2026-06-29: 4Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-05: 2Technical Details · 2026-07-08: 5Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 2Technical Details · 2026-07-16: 1Technical Details · 2026-07-19: 3Technical Details · 2026-07-21: 2Technical Details · 2026-07-23: 1Technical Details · 2026-08-01: 106-2906-3007-0107-0207-0507-0707-0807-1207-1307-1607-1907-2107-2207-2308-0109-06
Signal classification6 categories
Active Exploitation
1334.2%
Disclosure
821.1%
Patch
615.8%
Exploit
513.2%
PoC
410.5%
General
25.3%
Referenced assets42 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-294
Active Exploitation1Disclosure2Exploit1
2026-06-301
Disclosure1
2026-07-011
Disclosure1
2026-07-021
Patch1
2026-07-052
Exploit1Patch1
2026-07-071
Active Exploitation1
2026-07-089
Active Exploitation6Disclosure1General1Patch1
2026-07-121
Disclosure1
2026-07-132
Active Exploitation2
2026-07-161
Active Exploitation1
2026-07-193
Disclosure1Exploit2
2026-07-212
Disclosure1Patch1
2026-07-224
Exploit1PoC3
2026-07-233
Active Exploitation2Patch1
2026-08-011
Patch1
2026-09-062
General1PoC1
Full discourse20 posts
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The brief highlights multiple high‑value zero‑days that are actively exploited, with immediate patching advice for Microsoft AD FS, SharePoint, Cisco IOS, and other critical assets.

    33032123.8K
    125.1K followersView on X
  • YogSotho@YogSoth0
    Exploit

    #CVE-2026-56290 — #Joomla Page Builder CK #RCE Exploit Kit #exploit framework for CVE-2026-56290: Unauthenticated Arbitrary File Upload in Joomla Page Builder CK < 3.6.0 Features: - Scanner: Fast CIDR range scanning with multi-threaded fingerprinting - Fingerprinting: Detects Joomla, Page Builder CK, extracts version, identifies vulnerable endpoints - File Upload RCE: Exploits multiple CKEditor upload endpoints with extension bypass payloads - #Webshell Deployment: Deploys #PHP webshells (minimal, base64, AES-encrypted, CKEditor-compatible) - Interactive Shell: Full command execution via deployed webshell with batch support - Custom File Upload: Upload arbitrary PHP files #0days #security #cybersecurity #CVSS #hacking

    Post summary

    The post advertises an exploit kit that automates scanning, fingerprinting, and arbitrary file upload to abuse a Joomla Page Builder CK vulnerability (CVE-2026-56290), enabling remote code execution via webshell deployment.

    14029131.9K
    1.9K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-56290 PT ID: PT-2026-53285 Vendor: Joomla Product: http://JoomlaCK.fr Page Builder CK extension for Joomla Description: The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. Link: https://github.com/shinthink/pbck-exploit #dbugs_vuln

    Post summary

    A PoC and functional exploit for Joomla CK extension CVE-2026-56290 has been released, demonstrating an unauthenticated file upload vulnerability that results in full remote code execution.

    0402762.4K
    3.4K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Langflow vulnerability CVE-2026-55255, &amp; Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q &amp; apply mitigations to protect your org from cyberattacks. #InfoSec https://t.co/IsmhmuWqlr

    Post summary

    The post announces that three CVEs have been added to the DHS KEV catalog and urges users to apply mitigations to defend against active exploitation.

    0601717.5K
    302.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-56290 - critical 🚨 Page Builder CK &lt;= 3.5.10 - Unauthenticated Arbitrary File Upload &gt; Joomla Page Builder CK contains an unrestricted file upload vulnerability caused by l... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-56290 @pdnuclei #NucleiTemplates ...

    Post summary

    The post announces CVE-2026-56290, detailing a critical unauthenticated arbitrary file upload flaw in Joomla Page Builder CK up to version 3.5.10, without providing a PoC, exploit, patch notice, or evidence of active exploitation.

    030104548
    1.3K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Disclosure

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni #Zafiyet: Joomlack Page Builder - Hatalı Erişim Kontrolü (Improper Access Control) CVE Kodu: CVE-2026-56290 Zafiyet Türü: Hatalı Erişim Kontrolü (CWE-284) Fidye Yazılımı (Ransomware) Faaliyeti: Bilinmiyor 📌 Zafiyetin Özeti #Joomlack Page Builder üzerinde, hatalı erişim kontrolü (improper access control) kaynaklı kritik bir zafiyet tespit edilmiştir. Bu güvenlik açığı, kimliği doğrulanmamış (unauthenticated) saldırganların sisteme rastgele dosyalar yüklemesine ve bu yolla sunucu üzerinde uzaktan kod çalıştırmasına (remote code execution - RCE) olanak tanıyabilmektedir. 🛠️ Alınması Gereken Aksiyonlar 👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın. 👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin. 👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz dosya yüklemelerini engellemek için gerekli yapılandırmaları sağlayın. 👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.

    Post summary

    The bulletin discloses CVE-2026-56290, an improper access control flaw enabling RCE, and advises applying vendor patches and mitigations.

    13090161
    530 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/7追加) 🛡CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 SP Page Builder に存在する、危険なタイプのファイルの無制限アップロードの脆弱性です。 未認証の攻撃者が任意ファイルをアップロードし、最終的に PHP コードのアップロードおよび実行につなげられる可能性があります。 影響を受けるバージョンは SP Page Builder 1.0.0 から 6.6.1 までであり、6.6.2 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで SP Page Builder を使用している ・SP Page Builder 1.0.0 から 6.6.1 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・SP Page Builder 6.6.2 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意ファイルをアップロードされる可能性がある ・PHP ファイルを Web ルート配下に配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・不正な Super Administrator アカウントやバックドアを設置される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(mySites .guru) ・概要:mySites .guru は、SP Page Builder の asset.uploadCustomIcon タスクが認証チェックおよびサーバー側のファイル種別制限なしにアップロードを処理し、.php ファイルの配置と実行につながることを確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-48908 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/48xxx/CVE-2026-48908.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 ・https://www.joomshaper.com/page-builder ・https://www.joomshaper.com/forum/question/45152 ・https://extensions.joomla.org/extension/sp-page-builder/ ・https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html 🛡CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability ✅概要 ・深刻度:重要 8.4 (CVSS Base) / GitHub, Inc. (CNA) ・種別:ユーザ制御の鍵による認証回避 (CWE-639) ・CVSS:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L Langflow の /api/v1/responses エンドポイントに存在する IDOR の脆弱性です。 認証済みの攻撃者が、被害者の flow ID をリクエスト内で指定することで、別ユーザーに属する任意の flow を実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Langflow 1.9.1 未満を使用している ・攻撃者が対象 Langflow 環境へネットワーク経由でアクセスできる ・攻撃者が Langflow 上で認証済みである ・攻撃者が被害者の flow ID を取得または推測以外の手段で入手できる ・Langflow 1.9.1 以降へ更新されていない ✅悪用時影響 ・別ユーザーに属する flow を実行される可能性がある ・被害者 flow の実行コンテキストで機密情報や API キーの漏えいにつながる可能性がある ・マルチテナント環境でテナント境界を越えた不正操作につながる可能性がある ・Langflow 上の AI ワークフローや外部連携先の認証情報を悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Sysdig Threat Research Team) ・概要:Sysdig Threat Research Team は、事例を確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-55255 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/55xxx/CVE-2026-55255.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255 ・https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ・https://github.com/langflow-ai/langflow/pull/12832 ・https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e ・https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited ・https://jvndb.jvn.jp/ja/cwe/CWE-639.html 🛡CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 Page Builder CK に存在する、未認証の任意ファイルアップロードの脆弱性です。 攻撃者が認証なしで実行可能ファイルをアップロードし、リモートコード実行につなげられる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで Page Builder CK を使用している ・Page Builder CK 1.0 から 3.6.0 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意ファイルをアップロードされる可能性がある ・実行可能ファイルを任意の配置先に設置される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェルやバックドアを設置される可能性がある ・サイトの改ざん、情報窃取、追加侵害に利用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(mySites .guru) ・概要:mySites .guru は、Page Builder CK において認証なしで任意ファイルアップロードが可能であり、攻撃者が配置先フォルダを選択できるため、実行可能ファイルを配置して RCE につなげられると説明。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-56290 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/56xxx/CVE-2026-56290.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290 ・https://www.joomlack.fr/ ・https://www.joomlack.fr/en/joomla-extensions/page-builder-ck ・https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3 ・https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The text notes that CISA has added CVE‑2026‑48908, CVE‑2026‑55255, and CVE‑2026‑56290 to its Known‑Exploited Vulnerabilities catalog, with confirmed in‑the‑wild attacks, PoC details, and vendor patch information.

    001727.3K
    44.2K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical unauthenticated arbitrary file upload vulnerability #CVE-2026-56290 CVSS: 9.8. Affects the #Joomla Page Builder CK extension and leads to full #RCE. Actively exploited in the wild, with a public #PoC available! https://ccb.belgium.be/advisories/warning-critical-unauthenticated-arbitrary-file-upload-vulnerability-cve-2026-56290 #Patch #Patch #Patch

    Post summary

    CVE-2026-56290 is a critical unauthenticated file‑upload RCE vulnerability in the Joomla Page Builder CK extension, actively exploited in the wild, with a public PoC available and suggested patches.

    02021563
    7.2K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    PageBuilder CK's upload RCE (CVE-2026-56290) got only a login check in 3.6.0, so any Editor could still run code up to 3.6.2. Properly fixed in 3.6.3 - update now. https://mysites.guru/blog/pagebuilderck-file-upload-rce-incomplete-fix/?utm_source=twitter&utm_medium=social https://t.co/6oCg622iP6

    Post summary

    The message reports that PageBuilder CK’s upload RCE (CVE‑2026‑56290) is fixed in version 3.6.3, urging users to update, with no mention of PoC, exploit code or active attacks.

    00020104
    2.6K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-UkvAX0o [CRITICAL/PoC] Linked: CVE-2026-56290 CVE-2026-56290 🔗 https://exploitgrid.net/exploits/bb2db83d-7e39-433a-88a5-c096e08fe123

    Post summary

    A PoC for CVE-2026-56290 is available via ExploitGrid, with no further details on exploit tools, active attacks, or remediation.

    1000042
    40 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-27941 CVE-2026-31852 CVE-2026-56290 CVE-2026-7873 CVE-2023-42793 ..🧵👇

    Post summary

    A daily threat digest listed several CVE identifiers without providing additional context such as PoC details, exploit code, active exploitation, patches, or technical specifics.

    1000049
    40 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-56290 disclosed. CISA: CVE-2026-56290 added to Known Exploited Vulnerabilities — Joomlack Page Builder Status: ✅ Confirmed exploited in the wild Date added: 2026-07-07 Required action: Apply mitigations in accordance with vendor instructions,…

    Post summary

    CVE-2026-56290 was disclosed and is confirmed to be exploited in the wild; vendors should apply the recommended mitigations.

    1000056
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    CVE-2026-56290. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56290

    Post summary

    A PoC/exploit has been discovered for CVE-2026-56290, highlighting the availability of exploitation code but lacking information on active exploitation, patches, or detailed technical specifics.

    1000052
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56290

    Post summary

    A proof‑of‑concept exploit for CVE-2026-56290 has been discovered, but no active exploitation, patch information, or detailed technical data is provided.

    1000047
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for RCE 2026 exploit Posted: 2026-07-05T08:40:10.000Z Likes: 23 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56290

    Post summary

    The tweet announces that a PoC/exploit has been discovered for CVE‑2026‑56290, but offers no further technical or exploit details.

    1000048
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-56290: A PoC/exploit has been discovered for vulnerability CVE-2026-56290 PT ID: PT-2026-53285 Vendor: Joomla Product: Page Builder CK extension for Joomla Description: The Joomla extension Page Builder CK is vulnerable to an…

    Post summary

    A proof‑of‑concept exploit has been discovered for CVE-2026-56290 affecting the Joomla Page Builder CK extension, but no exploit code, patch, or evidence of active exploitation is provided.

    1000067
    326 followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    PageBuilder CK's upload RCE (CVE-2026-56290) got only a login check in 3.6.0, so any Editor could still run code up to 3.6.2. Properly fixed in 3.6.3 - update now. https://mysites.guru/blog/pagebuilderck-file-upload-rce-incomplete-fix/?utm_source=twitter&utm_medium=social https://t.co/8ypGE8hePQ

    Post summary

    The article notes that CVE‑2026‑56290, an upload RCE in PageBuilder CK, remained exploitable up to version 3.6.2 due to a missing login check, but was resolved with the 3.6.3 release, urging users to update.

    0001080
    2.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for RCE 2026 exploit Posted: 2026-06-29T21:16:49.000Z Likes: 20 0day Intel: #CVE-2026-56290 — #Joomla Page Builder CK #RCE Exploit Kit

    Post summary

    A new CVE-2026-56290 affecting Joomla Page Builder CK, identified as an RCE vulnerability, has been reported as a 0day Intel. No exploit code, PoC, or patch information is provided.

    1000077
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    #exploit framework for CVE-2026-56290: Unauthenticated Arbitrary File Upload in Joomla Page Builder CK &amp;lt; 3.6.0 0day Intel: #CVE-2026-56290 — #Joomla Page Builder CK #RCE Exploit Kit

    Post summary

    The brief announcement points to an available exploit framework and 0day intel for CVE‑2026‑56290, indicating that an exploit kit targeting the unauthenticated file upload flaw in Joomla Page Builder CK is circulating.

    1000084
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    CVE-2026-56290: #CVE-2026-56290 — #Joomla Page Builder CK #RCE Exploit Kit #exploit framework for CVE-2026-56290: Unauthenticated Arbitrary File Upload in Joomla Page Builder CK &amp;lt; 3.6.0 Features: Scanner: Fast CIDR range scanning with multi-threaded fingerprinting…

    Post summary

    An exploit kit targeting the unauthenticated arbitrary file upload vulnerability in Joomla Page Builder CK is announced, including a scanning component, but no evidence of active exploitation or remediation is provided.

    1000077
    326 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlackpage_builder_ck-joomla\!-

Explore more