LR pixel

What is the Vulnerability?

FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise.

Public proof-of-concept (PoC) exploit code is available, and active exploitation has been observed. The sustained increase in weekly exploitation activity indicates ongoing automated scanning campaigns targeting Internet-facing Joomla servers, highlighting the need for immediate patching and monitoring of vulnerable deployments.

What is the recommended Mitigation?

• Upgrade SP Page Builder to version 6.6.2 or later.

• Restrict public access to Joomla administrative interfaces.

• Prevent PHP execution from upload/media directories.

• Monitor for unexpected PHP files and newly created administrator accounts.

• Review web server logs for suspicious POST requests targeting the SP Page Builder upload endpoint.

What FortiGuard Coverage is available?

• FortiGuard Intrusion Prevention System (IPS) protects against exploitation attempts targeting vulnerable SP Page Builder deployments.

Intrusion Prevention | FortiGuard Labs


• FortiGuard Web Filtering blocks access to known malicious domains, command-and-control infrastructure, and payload hosting locations associated with post-exploitation activity.

• FortiGuard Antivirus detects and blocks malicious payloads, web shells, backdoors, and other malware that attackers may deploy after successfully exploiting vulnerable Joomla installations.

• FortiEDR detects suspicious post-exploitation activities, including unauthorized command execution, web shell execution, persistence attempts, credential theft, and lateral movement from compromised Joomla servers.

• FortiGuard Incident Response Service helps organizations investigate suspected compromises, identify attacker activity, determine the scope of impact, and support containment, remediation, and recovery efforts following exploitation.