DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-56290PUBLISHED: 2026-07-07
CRITICALCVE-2026-56290★ CISA KEV LISTED

Joomlack Page Builder CK Unauthenticated Arbitrary File Upload / RCE

VENDOR: Joomlack//PRODUCT: Page Builder CK for Joomla
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

An improper access control vulnerability in Joomlack's Page Builder CK for Joomla allows unauthenticated attackers to upload arbitrary executable files and achieve full remote code execution. Exploitation delivering web shells was observed as early as June 27, 2026, by the mySites.guru site management service. CISA added to KEV on July 7 with a federal patch deadline of July 10; update to Page Builder CK version 3.6.0 or later.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSPage Builder CK for Joomla versions prior to 3.6.0
  • https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
  • https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
  • https://threat-modeling.com/cve-2026-48908-cve-2026-56290-joomla-page-builders-cisa-kev/
  • https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn