A zero-day vulnerability in the Joomla extension iCagenda allowed attackers to upload arbitrary files and achieve remote code execution (RCE), and the issue was addressed in version 4.0.8. The flaw fit the well-known pattern of unrestricted file upload, where weak validation of uploaded content lets an attacker place executable or otherwise dangerous files on a target server.
OWASP guidance on unrestricted file upload shows how such weaknesses can be exploited through manipulated filenames, extensions, content types, parser behavior, and downstream file processing, leading to outcomes including server compromise, denial of service, phishing, malware hosting, defacement, and information disclosure. Recommended mitigations include strict allow lists, randomized filenames, storing uploads outside executable paths, enforcing size and authorization controls, scanning uploads, and applying secure response headers to reduce the risk of similar upload-to-RCE attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-48939, an unauthenticated file upload RCE in the Joomla iCagenda extension, to its Known Exploited Vulnerabilities catalog. The listing reflected active exploitation and triggered federal remediation requirements under BOD 22-01.
A mySites.guru post reports that a zero-day unrestricted file upload vulnerability leading to remote code execution in iCagenda was fixed in version 4.0.8. The reference does not provide a specific event date beyond the publication context.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcethreataft.com
Open sourcecvereports.com
Open sourcejoomlic.com
Open sourceowasp.org
Open sourcemysites.guru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.