Skip to main content
ssrushti
Staff
Staff
July 20, 2026

Outbreak Alert: Joomla SP Page Builder RCE

  • July 20, 2026
  • 0 replies
  • 27 views

FortiRecon Digital Risk Protection (DRP), a SaaS-based service, includes External Attack Surface Management, Brand Protection, and Adversary Centric Intelligence.

Adversary Centric Intelligence (ACI): leverages FortiGuard Threat Analysis to provide comprehensive coverage of dark web, open-source, and technical threat intelligence, including threat actor insights to enable organizations to respond proactively assess risks, respond faster to incidents, better understand their attackers, and guard assets.

The Vulnerability Intelligence Module under Adversary Centric Intelligence (ACI) provides a realistic view of the impact of the vulnerability based upon chatter and discussion of the same across various external sources such as Darkweb, social media, News / Blogs etc.

CVE ID

CVE-2026-48908

CVE Title

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

NVD Severity

Not Assigned

FortiRecon Severity

CRITICAL

FortiRecon Score

95/100

Epss Score

0.01569

Exploited

Yes

Exploited by Ransomware Group(s)

No

Exploited by APT Group(s)

No

Included in CISA KEV List

Yes

Available working exploit(s)

0

Available POC exploit(s)

9

Darknet Mention(s)

3 (crdclub, gerki)

Telegram Mention(s)

0

FortiRecon Intelligence Reporting(s)

4 (OSINT), 3 (FortiGuard Research), 3 (Darknet)

Vendor Advisory:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!