2026-07-10HIGHexploitedCISA KEV-lists an actively-exploited unauth RCE in the iCagenda Joomla extension, RCE hits Joomla 6, auth bypass hits all versions
iCagenda for Joomla, unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV
cve · CVE-2026-48939
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
CISA KEV-lists an actively-exploited unauth RCE in the iCagenda Joomla extension, RCE hits Joomla 6, auth…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology · regions: europe
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-48939, newest first. Check the date before acting on an older one.
- Update iCagenda to ≥ 4.0.8 (current branch) or ≥ 3.9.15 (legacy branch) on every Joomla site now; unpublishing the component does not protect it; the submit endpoint and any uploaded files stay reachable.2026-07-10CVE-2026-48939
- On Joomla 6 sites assume pre-patch compromise: hunt for any file that should not exist under images/icagenda/frontend/attachments/ (a .php file there is a web shell until proven otherwise), and if found, treat the whole site as compromised and rotate Joomla secrets.2026-07-10CVE-2026-48939
- On Joomla 2.5–5 sites, check the event-submission queue for anonymously-created unapproved events as a sign the access bypass was used.2026-07-10CVE-2026-48939
Defender insights
What each entry about CVE-2026-48939 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-10/cve-2026-48939-icagenda-joomla-unauth-file-upload-rce-kev · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-10/cve-2026-48939-icagenda-joomla-unauth-file-upload-rce-kev · ATT&CK page ↗
Entries about iCagenda for Joomla, unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- cisa.gov1 (50%)
- mysites.guru1 (50%)