Joomla SP Page Builder RCE
ID: 8742edda-dd49-5e22-acac-1fea54a03294
STIX ID: report--8742edda-dd49-5e22-acac-1fea54a03294
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
FortiGuard Labs reports active exploitation of CVE-2026-48908, a critical (CVSS 10.0) unauthenticated RCE in the JoomShaper SP Page Builder for Joomla that allows unrestricted file uploads and remote PHP execution; telemetry shows thousands of blocked attempts, the flaw has been added to CISA's KEV, and organizations are urged to upgrade to SP Page Builder 6.6.2 and investigate for web shells, unauthorized administrator accounts, and other persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
