DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // CISA KEV 2026-07-07 // PUBLISHED 2026-07-07

CISA KEV: JoomShaper SP Page Builder Unauthenticated File Upload RCE (CVE-2026-48908)

JoomShaper SP Page Builder contains a CVSS 10.0 unrestricted file upload vulnerability allowing unauthenticated users to upload and execute arbitrary PHP code. It was exploited as a zero-day via HTTP POST to the 'index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon' endpoint, resulting in new rogue Super User accounts being created on victim Joomla sites. The threat activity is assessed as opportunistic and financially motivated.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
JoomShaper SP Page Builder all versions prior to 6.6.2
CRITICAL
PUBLIC
PATCHED

Update SP Page Builder to version 6.6.2 or later immediately. Audit the Joomla installation for unexpected Super User accounts created after any plausible exploitation window and remove them. Restrict write permissions on the upload directories if patching is delayed.

Search web server access logs for POST requests to 'index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon'. Hunt for newly created .php files in Joomla asset/upload directories with recent timestamps. Audit administrator-level accounts for unexpected additions.

  • https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
  • https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
  • https://nvd.nist.gov/vuln/detail/CVE-2026-48908
  • https://extensions.joomla.org/extension/sp-page-builder/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn