In Joomla versions 3.2.1 through 3.9.14, versions 4.0.0 through 4.0.7 a critical severity vulnerability CVE-2026-48939 was detected. This vulnerability allows attackers to upload arbitrary files via the iCagenda file attachment feature, enabling PHP code upload and remote code execution. To address this issue, users should upgrade Joomla to version 3.9.15 and 4.0.8 (or later). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-48939.
Joomla: Arbitrary File Upload in iCagenda Extension Leading to Remote Code Execution
by the Hossted team
06.07.2026