CVE
CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Exploitation IoCs 9
Domain xs[.]xxooonline[.]eu[.]cc
Filename .bd.php
Filename .brq-*.php
Filename .wp-log.php
Filename down.php
Filename images/baforms/uploads
Filename images/icagenda/frontend/attachments/
IP 137[.]175[.]93[.]126
IP 43[.]108[.]17[.]80
MITRE ATT&CK TTPs 15
T1021 T1027 T1046 T1059 T1059.001 T1071 T1071.001 T1078 T1082 T1090 T1105 T1133 T1190 T1505.003 T1566
Remote Services
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Network Service Discovery
Discovery
Command and Scripting Interpreter
Execution
PowerShell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Web Shell
Persistence
Phishing
Initial Access
Source Articles
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. CISA has added two critical vulnerabilities in Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog due to active zero-day exploitation. CVE-2026-48939 and CVE-2026-56291, both rated 10.0 CVSS, allow unauthenticated remote code execution via arbitrary file upload. These flaws are being exploited in automated attacks to deploy web shells on vulnerable Joomla sites. Australia's ACSC has also warned of a global campaign exploiting similar CMS vulnerabilities.
hacker-news Jul 13, 2026
Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) has issued a warning about a global campaign targeting vulnerabilities in content management systems (CMS) and plugins, affecting numerous small- to medium-sized businesses in Australia. Threat actors are actively scanning for exposed CMS platforms and deploying webshells to gain persistent access, enabling credential theft, service disruption, and lateral movement. The campaign exploits known vulnerabilities across multiple CMS platforms including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE, with potential AI assistance to accelerate exploitation.
bleeping-computer Jul 11, 2026
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
hacker-news Jul 10, 2026