Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities FortiGuard Outbreak Alerts

Joomla SP Page Builder RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-48908, CVSS 9.8) exists in the JoomShaper SP Page Builder extension for Joomla due to an unrestricted file upload in the `asset.uploadCustomIcon` endpoint. The NVD data indicates all versions of the Ollyo SP Page Builder prior to version 6.6.2 are affected. The fix requires an immediate upgrade to SP Page Builder version 6.6.2, and organizations must also investigate for existing compromises such as web shells.
Read Full Article →

Outbreak Alert Joomla SP Page Builder RCE Released: Jul 17, 2026 Share Joomla SP Page Builder RCE Vulnerability Tags High Severity Joomla Platform Share Subscribe Overview Analysis Solutions Threat Intelligence References Subscribe Overview Analysis Solutions Threat Intelligence References Unrestricted Upload of File Vulnerability FortiGuard Labs continues to observe active exploitation of CVE-2026-48908, a critical unauthenticated remote code execution vulnerability affecting the JoomShaper SP Page Builder extension for Joomla. At the time of release, FortiGuard telemetry recorded 1,210 blocked exploitation attempts in the last 24 hours and 15,626 attempts over the past 7 days. Learn More » Common Vulnerabilities and Exposures CVE-2026-48908 Background CVE-2026-48908 is a critical (CVSS 10.0) unauthenticated remote code execution (RCE) vulnerability affecting the JoomShaper SP Page Builder extension for Joomla. The vulnerability stems from an unrestricted file upload in the asset.uploadCustomIcon endpoint, allowing remote attackers to upload and execute arbitrary PHP files without authentication. The flaw is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. At the time of release, the highest attack volumes targeted organizations in Poland, Turkey, Australia, and the United States, with the Telecommunications/Carrier and Technology sectors experiencing the greatest activity. Click here to analyze the Real-Time Threat Map Latest Development Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered. Organizations should immediately upgrade to SP Page Builder 6.6.2 or later and investigate systems for web shells, unauthorized administrator accounts, and other persistence mechanisms, as patching alone does not remove an existing compromise. July 07, 2026: CISA adds CVE-2026-48908 to the Known Exploited Vulnerabilities (KEV) Catalog, confirming evidence of active exploitation in the wild and requiring rapid remediation by U.S. federal agencies. June 20, 2026: JoomShaper releases SP Page Builder 6.6.2, which fixes the unrestricted file upload vulnerability https://www.joomshaper.com/forum/question/45152 FortiGuard Cybersecurity Framework Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services. PROTECT IPS DETECT IOC Outbreak Detection RESPOND Automated Response Assisted Response Services RECOVER NOC/SOC Training End-User Training IDENTIFY Attack Surface Hardening IPS Detects and blocks attack attempts leveraging the vulnerability FortiADC DB 36.251 FortiGate DB 36.251 FortiNDR DB 36.251 FortiNDR Cloud DB 36.251 FortiProxy DB 36.251 FortiSASE DB 36.251 IOC FortiAnalyzer FortiCloud SOCaaS FortiSIEM FortiSOAR Outbreak Detection FortiAnalyzer DB 3.00000 Automated Response Services that can automaticlly respond to this outbreak. FortiXDR Assisted Response Services Experts to assist you with analysis, containment and response activities. Incident Response NOC/SOC Training Train your network and security professionals and optimize your incident response to stay on top of the cyberattacks. NSE Training Response Readiness End-User Training Raise security awareness to your employees that are continuously being targeted by phishing, drive-by download and other forms of cyberattacks. Security Awareness & Training Attack Surface Hardening Check Security Fabric devices to build actionable configuration recommendations and key indicators. Security Rating Threat Intelligence Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities. ✖ References Sources of information in support and relation to this Outbreak and vendor. Vendor Advisory Learn More » About FortiGuard Outbreak Alerts Learn More »

Share this article