CVE-2026-48908
Known exploited · CISA KEV
EPSS 15% (97th percentile).
CISA federal remediation date Jul 10
Vulnerabilities & Exploits · Zero-Day Exploit
A convenience upload feature in SP Page Builder now acts as a server takeover path. An unauthenticated attacker can abuse the custom-icon upload function to place PHP on the host and run code, so patching alone does not rule out a hidden shell or stolen admin access already left behind.
CSIRT-ITA says CVE-2026-48908 is being actively exploited in SP Page Builder, and the vendor has fixed it in 6.6.2. The flaw affects versions before 6.6.2 and comes from weak access checks on the icon upload path, which lets remote users upload crafted PHP instead of an image.
The follow-on risk is persistence. The advisory calls out unknown Super Administrator accounts, suspicious PHP files, and compromised Joomla, SSH, and FTP credentials as signs the attacker may still be inside after the update.
1 source · Jun 26
Known exploited · CISA KEV
EPSS 15% (97th percentile).
CISA federal remediation date Jul 10
CSIRT Italia / ACN
Joomla SP Page Builder: sfruttamento attivo in rete della CVE-2026-48908
Rilevato sfruttamento attivo in rete della CVE-2026-48908 – già sanata dal vendor – presente nel plugin SP Page Builder per il noto CMS Joomla!
originalPart of the PlainSec briefing for 2026-06-26
Every edition of this story: Joomla Plugin Upload Feature Becomes Server Takeover Path