CVE-2026-48908
Known exploited · CISA KEV
EPSS 15% (97th percentile).
CISA federal remediation date Jul 10
Vulnerabilities · 80 days ago
A convenience upload feature in SP Page Builder now acts as a server takeover path. An unauthenticated attacker can abuse the custom-icon upload function to place PHP on the host and run code, so patching alone does not rule out a hidden shell or stolen admin access already left behind.
CSIRT-ITA says CVE-2026-48908 is being actively exploited in SP Page Builder, and the vendor has fixed it in 6.6.2. The flaw affects versions before 6.6.2 and comes from weak access checks on the icon upload path, which lets remote users upload crafted PHP instead of an image.
The follow-on risk is persistence. The advisory calls out unknown Super Administrator accounts, suspicious PHP files, and compromised Joomla, SSH, and FTP credentials as signs the attacker may still be inside after the update.
Known exploited · CISA KEV
EPSS 15% (97th percentile).
CISA federal remediation date Jul 10
1 source covering this story
Joomla SP Page Builder: sfruttamento attivo in rete della CVE-2026-48908
Rilevato sfruttamento attivo in rete della CVE-2026-48908 – già sanata dal vendor – presente nel plugin SP Page Builder per il noto CMS Joomla!
Part of the PlainSec briefing for 2026-06-27