CISA has added two Joomla extension vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation against SP Page Builder and Page Builder CK. The flaws, tracked as CVE-2026-48908 and CVE-2026-56290, are unauthenticated arbitrary file upload bugs that allow attackers to place malicious files on exposed Joomla sites and achieve remote code execution.
Security reporting says the vulnerabilities have been used to upload web shells, deploy PHP file-manager backdoors, and create hidden administrator accounts for persistence on compromised systems. Vendor fixes are available, including SP Page Builder 6.6.2 for the zero-day issue, and defenders are being urged to patch immediately or temporarily disable the affected extensions and restrict public access to vulnerable upload endpoints until remediation is complete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-48908 and CVE-2026-56290 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The advisory says attackers had used the flaws to upload web shells, deploy PHP file manager backdoors, and create hidden administrator accounts.
A disclosure detailed an unauthenticated file upload vulnerability in Page Builder CK that could lead to remote code execution on vulnerable Joomla sites. The issue was later identified as CVE-2026-56290 in the provided references.
A zero-day unauthenticated file upload vulnerability affecting SP Page Builder was fixed by the vendor in version 6.6.2. The flaw could allow remote code execution on vulnerable Joomla sites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
labs.beazley.security
Open sourceforum.joomlack.fr
Open sourcemysites.guru
Open sourcemysites.guru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.