DIRAS TAKE
Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a July 13, 2026 federal remediation deadline, and no vendor fix is listed — treat exposed installs as high priority to isolate and mitigate immediately.
What is CVE-2026-48939?
An unauthenticated remote attacker can upload and execute arbitrary PHP on iCagenda, allowing full compromise of affected Joomla sites; this is tracked as CVE-2026-48939. The vulnerability affects iCagenda 3.x releases from 3.2.1 through 4.0.7 and arises from an unrestricted file upload in the attachment feature, requiring only network access to a site running the vulnerable extension. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of iCagenda iCagenda are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.2.1-4.0.7 |
Is CVE-2026-48939 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-10, requiring US federal agencies to remediate by 2026-07-13; public exploit code is also available.
How to fix CVE-2026-48939
- Follow vendor guidance and apply any vendor-provided mitigations immediately.
- If a patch is unavailable, remove or disable the iCagenda extension from internet-facing Joomla sites.
- Restrict access to the site (IP allowlist, web application firewall) and block file upload endpoints.
- Monitor web and application logs for suspicious upload activity and signs of PHP webshells.
Frequently asked questions
Is CVE-2026-48939 being actively exploited?
CISA added CVE-2026-48939 to its Known Exploited Vulnerabilities catalog on 2026-07-10 and set a remediation deadline of 2026-07-13; public exploit code is also available.
Which iCagenda versions are affected by CVE-2026-48939?
iCagenda versions 3.2.1 through 4.0.7 (3.x branch) are listed as affected.
Is there a patch for CVE-2026-48939?
No fixed version is listed for CVE-2026-48939 in the available advisory information; follow vendor mitigations or remove the extension until a patch is released.
Does CVE-2026-48939 require authentication?
No; the vulnerability allows unauthenticated file upload and remote code execution on affected iCagenda installations.
References
- nvd.nist.gov/vuln/detail/CVE-2026-48939
- cve.org/CVERecord?id=CVE-2026-48939
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939
- icagenda.com
- All iCagenda CVEs on CVE Radar
- CVEs published in September 2026