CVE
CVE-2026-3395
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
Exploitation IoCs 2
Filename images/baforms/uploads
Filename images/icagenda/frontend/attachments/
MITRE ATT&CK TTPs 14
T1021 T1046 T1059 T1059.001 T1071 T1071.001 T1078 T1082 T1090 T1105 T1133 T1190 T1505.003 T1566
Remote Services
Lateral Movement
Network Service Discovery
Discovery
Command and Scripting Interpreter
Execution
PowerShell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Web Shell
Persistence
Phishing
Initial Access
Source Articles
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. CISA has added two critical vulnerabilities in Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog due to active zero-day exploitation. CVE-2026-48939 and CVE-2026-56291, both rated 10.0 CVSS, allow unauthenticated remote code execution via arbitrary file upload. These flaws are being exploited in automated attacks to deploy web shells on vulnerable Joomla sites. Australia's ACSC has also warned of a global campaign exploiting similar CMS vulnerabilities.
hacker-news Jul 13, 2026
Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) has issued a warning about a global campaign targeting vulnerabilities in content management systems (CMS) and plugins, affecting numerous small- to medium-sized businesses in Australia. Threat actors are actively scanning for exposed CMS platforms and deploying webshells to gain persistent access, enabling credential theft, service disruption, and lateral movement. The campaign exploits known vulnerabilities across multiple CMS platforms including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE, with potential AI assistance to accelerate exploitation.
bleeping-computer Jul 11, 2026