FortiGuard Labs reported ongoing in-the-wild exploitation of CVE-2026-48908, a critical CVSS 10.0 unauthenticated remote code execution flaw in the JoomShaper SP Page Builder extension for Joomla. The bug stems from an unrestricted file upload in the asset.uploadCustomIcon functionality that lets attackers upload and execute arbitrary PHP files, enabling full server compromise. Public proof-of-concept exploit code is available, and the vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog after active abuse was confirmed.
FortiGuard said exploitation has remained elevated, with 1,210 blocked attempts in 24 hours and 15,626 over 7 days, indicating sustained automated scanning of Internet-facing Joomla servers. The highest attack volumes were observed against organizations in Poland, Turkey, Australia, and the United States, with Telecommunications/Carrier and Technology among the most targeted sectors. Defenders were urged to upgrade to SP Page Builder 6.6.2 or later, restrict public access to Joomla administrative interfaces, block PHP execution in upload directories, and investigate for web shells, suspicious files, unauthorized administrator accounts, and other persistence because patching alone does not remove an existing compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs reported 1,210 blocked exploitation attempts against CVE-2026-48908 in the previous 24 hours, highlighting sustained attack activity against the vulnerable Joomla extension.
FortiGuard telemetry recorded 15,626 blocked exploitation attempts targeting CVE-2026-48908 over the previous seven days, with the highest volumes observed against organizations in Poland, Turkey, Australia, and the United States.
FortiGuard Labs reported continued active exploitation attempts against vulnerable Joomla SP Page Builder installations via CVE-2026-48908, with public proof-of-concept exploit code available and elevated weekly activity indicating ongoing automated scanning of Internet-facing Joomla servers.
CISA added CVE-2026-48908 to its Known Exploited Vulnerabilities catalog, reflecting that the Joomla SP Page Builder flaw was being exploited in the wild.
JoomShaper released SP Page Builder version 6.6.2 to remediate CVE-2026-48908, a critical unauthenticated remote code execution flaw caused by unrestricted PHP file upload in the custom icon upload functionality.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourcefortiguard.fortinet.com
Open sourcejoomshaper.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.