CVE-2026-48939: Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE
HoneyLabs honeypots recorded 82 probes matching CVE-2026-48939 from 16 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /administrator
- /images/icagenda/frontend/attachments/.txt
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 185.177.72.56 | 14 | Bucklog SARL | France |
| 185.177.72.5 | 14 | Bucklog SARL | France |
| 194.180.49.37 | 12 | MEVSPACE sp. z o.o. | Bulgaria |
| 195.128.248.33 | 8 | Virtual Systems LLC | Ukraine |
| 213.209.159.175 | 5 | Feo Prest SRL | Taiwan |
| 185.177.72.70 | 4 | Bucklog SARL | France |
| 195.178.110.28 | 4 | Techoff Srv Limited | Bulgaria |
| 213.209.159.154 | 4 | Feo Prest SRL | Taiwan |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS211590 | Bucklog SARL | 45 | 9 |
| AS201814 | MEVSPACE sp. z o.o. | 12 | 1 |
| AS208137 | Feo Prest SRL | 9 | 2 |
| AS6698 | Virtual Systems LLC | 8 | 1 |
| AS48090 | Techoff Srv Limited | 4 | 1 |
| AS396356 | Latitude.sh | 2 | 1 |
Captured requests
- /administrator/.env?id=4096631342&x=4145975837&b=18428560583698009965
- /administrator/config%2ecfg
- /administrator/logs/
- /administrator/config/.env
HTTP client fingerprints (JA4H)
- ge11nn0300_88b8dd6ae43e
- ge11nn14en_068ebe3632ec
- ge11nn0400_cf1edba2959c
- ge11nr20en_b917adf100af
CVE report
CVE report
Open a specific CVE from the CVE tracker.