All CVEs
Vulnerability intelligence

CVE-2026-48939

CWE-434

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVSS Score
10
Critical
EPSS — Exploit Probability
83%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-10
Remediation
Patch available
Federal deadline 2026-07-13
NVD entry Vendor patch PoC / advisory CISA KEV

6 articles across 5 outlets · first covered Jul 10, 2026 · latest Jul 13, 2026

Tracked incidents

Associated threat actors

Coverage timeline