2026-07-08NOTABLEexploitedTwo Joomla page-builder extensions (SP Page Builder, Page Builder CK) hit KEV for unauth file-upload RCE zero-days
JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day
cve · CVE-2026-48908
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
Two Joomla page-builder extensions (SP Page Builder, Page Builder CK) hit KEV for unauth file-upload RCE…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology
Sources cited
3
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-48908, newest first. Check the date before acting on an older one.
- Update SP Page Builder to ≥ 6.6.2 and Page Builder CK to ≥ 3.6.0 (or the 3.1.1 / 3.4.10 back-ports) on every Joomla site running them.2026-07-08CVE-2026-48908 +1
- Hunt for newly created Joomla Super User / Super Administrator accounts (especially @secure.local addresses) and web shells written under the site web root; patching the entry point does not remove an already-planted admin account.2026-07-08CVE-2026-48908 +1
Defender insights
What each entry about CVE-2026-48908 tells a defender to do, newest first.
Story timeline
Entries about JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- mysites.guru2 (67%)
- thehackernews.com1 (33%)
External references
All cited sources (3)
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html