CVE-2026-48939: Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE

HoneyLabs honeypots recorded 82 probes matching CVE-2026-48939 from 16 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /administrator
  • /images/icagenda/frontend/attachments/.txt

Addresses probing it

Source IPProbesNetworkCountry
185.177.72.5614Bucklog SARLFrance
185.177.72.514Bucklog SARLFrance
194.180.49.3712MEVSPACE sp. z o.o.Bulgaria
195.128.248.338Virtual Systems LLCUkraine
213.209.159.1755Feo Prest SRLTaiwan
185.177.72.704Bucklog SARLFrance
195.178.110.284Techoff Srv LimitedBulgaria
213.209.159.1544Feo Prest SRLTaiwan

Networks it comes from

ASNOrganisationProbesSource IPs
AS211590Bucklog SARL459
AS201814MEVSPACE sp. z o.o.121
AS208137Feo Prest SRL92
AS6698Virtual Systems LLC81
AS48090Techoff Srv Limited41
AS396356Latitude.sh21

Captured requests

  • /administrator/.env?id=4096631342&x=4145975837&b=18428560583698009965
  • /administrator/config%2ecfg
  • /administrator/logs/
  • /administrator/config/.env

HTTP client fingerprints (JA4H)

  • ge11nn0300_88b8dd6ae43e
  • ge11nn14en_068ebe3632ec
  • ge11nn0400_cf1edba2959c
  • ge11nr20en_b917adf100af

CVE report

CVE report

Open a specific CVE from the CVE tracker.