CISA says attackers are actively exploiting two Joomla page-builder extensions and agencies must patch by July 10. The flaws are CVE-2026-48908 in JoomShaper SP Page Builder before 6.6.2 and CVE-2026-56290 in Joomlack Page Builder CK before 3.6.0. Both are unauthenticated file-upload or access-control bugs that can lead to remote code execution, and reports say attackers have used them to plant hidden admin accounts, web shells, and PHP file manager backdoors.
Why it matters: Website owners using these Joomla extensions could have their sites quietly taken over and used to host backdoors or malicious content. Patch immediately, check for unexpected administrator accounts and uploaded PHP files, and review server logs for suspicious uploads.
2026.07.14
93% relevant
This article appears to cover the same underlying KEV event for two actively exploited Joomla extension file-upload flaws leading to web-shell deployment, but with corrected CVE IDs and specific affected extensions: iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291). It adds details on attack timing, exploit behavior, and patch versions.
Ionut Arghire
2026.07.08
100% relevant
No existing tracked story covers these specific Joomla extension exploitation events or CISA KEV additions, so this article establishes a new story anchored to CVE-2026-48908 and CVE-2026-56290.
← Back to all stories