DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-48908PUBLISHED: 2026-06-20
CRITICALCVE-2026-48908★ CISA KEV LISTED

JoomShaper SP Page Builder Unauthenticated File Upload / RCE (Zero-Day)

VENDOR: JoomShaper//PRODUCT: SP Page Builder for Joomla
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

The asset.uploadCustomIcon endpoint in SP Page Builder performs no authentication checks and no file-type validation, allowing unauthenticated attackers to upload PHP webshells to web-accessible directories via a single HTTP POST request and achieve full RCE. Exploitation was observed in the wild as a zero-day before the patch shipped on June 14; post-exploitation activity includes creation of hidden Joomla Super Administrator accounts and persistent PHP file-manager backdoors. Approximately 194,793 web properties are estimated to load the affected component; public PoC is available and botnet scanning is confirmed active. CISA added to KEV July 7.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
AFFECTED VERSIONSSP Page Builder versions 1.0.0 through 6.6.1 (all versions prior to 6.6.2)
  • https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
  • https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
  • https://www.ionix.io/threat-center/cve-2026-48908/
  • https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
SHARE BRIEF:✕ Post on Xin Share on LinkedIn