iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
A critical vulnerability (CVE-2026-48939) in iCagenda, a calendar and event management extension for Joomla, allows attackers to upload arbitrary files, including malicious PHP code, through its file attachment feature. This unrestricted file upload flaw can lead to remote code execution, enabling attackers to take control of affected systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of this vulnerability in the wild and added it to their Known Exploited Vulnerabilities catalog on July 10, 2026. The vulnerability affects all websites using vulnerable versions of the iCagenda extension, potentially exposing them to complete system compromise. As this is being actively exploited, administrators are urged to immediately update to a patched version or apply mitigation measures. The inclusion in CISA's catalog means federal agencies must remediate this vulnerability by July 31, 2026, but all organizations using iCagenda should treat this as a high-priority security issue due to the active threat.
Key Takeaways
- CVE-2026-48939 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- This critical-severity vulnerability affects iCagenda Unrestricted Upload of File with Dangerous Type and could lead to system compromise.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- iCagenda iCagenda: iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.