CISA adds exploited Joomla extension flaws CVE-2026-48908 and CVE-2026-56290 to KEV after web-shell attacks

CISA says attackers are actively exploiting two Joomla page-builder extensions and agencies must patch by July 10. The flaws are CVE-2026-48908 in JoomShaper SP Page Builder before 6.6.2 and CVE-2026-56290 in Joomlack Page Builder CK before 3.6.0. Both are unauthenticated file-upload or access-control bugs that can lead to remote code execution, and reports say attackers have used them to plant hidden admin accounts, web shells, and PHP file manager backdoors.
Why it matters: Website owners using these Joomla extensions could have their sites quietly taken over and used to host backdoors or malicious content. Patch immediately, check for unexpected administrator accounts and uploaded PHP files, and review server logs for suspicious uploads.

Sources

Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
2026.07.14 93% relevant
This article appears to cover the same underlying KEV event for two actively exploited Joomla extension file-upload flaws leading to web-shell deployment, but with corrected CVE IDs and specific affected extensions: iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291). It adds details on attack timing, exploit behavior, and patch versions.
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Ionut Arghire 2026.07.08 100% relevant
No existing tracked story covers these specific Joomla extension exploitation events or CISA KEV additions, so this article establishes a new story anchored to CVE-2026-48908 and CVE-2026-56290.
← Back to all stories