A critical vulnerability in iCagenda , the most popular event-calendar extension for Joomla, has been actively exploited by attackers worldwide since early July 2026 , according to an announcement from Joomlic, the developer. The flaw, listed as CVE-2026-48939 , allows unauthenticated users to upload arbitrary files to the server and result in full remote code execution (RCE). The developer released an emergency patch with iCagenda version 4.0.8 , classifying the update as a “Critical Security release” and urging all administrators to apply it immediately.

iCagenda is one of the most widely used Joomla extensions, installed on tens of thousands of sites worldwide — from small local communities to corporate portals that use it to manage events, calendars, and public events. The widespread installation of the extension dramatically increases the attack surface, especially since many sites are left without direct administrator supervision on weekends — precisely the period when attacks are most prevalent.
What is the vulnerability in iCagenda?
The CVE-2026-48939 iCagenda vulnerability is located in the guest event submission routine, the feature that allows visitors to submit new events without having an account in Joomla. The flaw allows unauthenticated visitors to upload executable files to the server without adequate mime-type or extension checking. A malicious PHP file disguised as an event image is enough to place a web shell on the site and initiate a full compromise.
The developer confirms via the Joomlic news page that the vulnerability is actively exploited in the wild, with attackers having been recorded targeting Joomla 6 sites where the vulnerability is most critical. However, the vulnerable path exists in all Joomla versions, making the update necessary for every iCagenda installation regardless of the underlying Joomla version.
How the attack works
The iCagenda attack chain is mechanically simple but devastatingly effective. First, the attacker locates a Joomla site running iCagenda prior to version 4.0.8 by simply searching for public URL patterns (`/components/com_icagenda/`). Second, he uses the public event submission form and uploads a file with a malicious PHP payload disguised as a promotional image.
Third step, it exploits insufficient validation of mime-type and file extension: the tool superficially checks the headers but allows the file to be saved with a dangerous extension. Fourth, it directly calls the uploaded file from the known path /images/com_icagenda/ or similar, triggering code execution. Fifth, it installs a persistent web shell and gains full control of the site, including access to the database and credentials of other services.

See also: HalluSquatting: New attack tricks AI coding assistants into malicious code
Affected iCagenda versions
The vulnerability affects an extremely wide range of versions, covering virtually any site that has not had time to upgrade to the latest release. According to the official documentation for version 4.0.8, the vulnerable builds are:
First, the 4.x series before 4.0.8 — that is, all versions 4.0.0 to 4.0.7 installed from the beginning of 2026 onwards. Second, the legacy 3.x series before 3.9.15, which still runs on older Joomla 3 installations. Third, all versions that have not received the security updates of the last few months, regardless of the underlying Joomla version (3, 4, 5 or 6).
See also: Joomla: Fixes vulnerabilities that allow RCE attacks
Immediate protective measures
The SecNews technical team recommends the following measures in strict order of priority. First and foremost: upgrade to iCagenda 4.0.8 (or backport 3.9.15 for legacy installations) via the Joomla update manager. The upgrade is simple and does not require any configuration changes — it simply closes the gap. The manufacturer has made the patch available free of charge to all users, even those without an active support subscription.

Second measure, while the upgrade is not immediately possible: temporarily disable guest event submission from the extension management, if the site does not need this feature. Third: scan the site for suspicious files in the folders /images/com_icagenda/, /images/icagenda/ and /media/com_icagenda/. Look for PHP, .phtml or .htaccess files that have no identifiable origin or have a recent creation date.
Fourth measure: check the Joomla access log for POST requests to the event submission form endpoint from unknown IP addresses in the last 30 days, as active exploitation has already been recorded on many sites. Fifth: install a Web Application Firewall (WAF) with rules that filter uploads with suspicious extensions or double-extension patterns (`file.jpg.php`) — a practice that prevents not only the iCagenda vulnerability but also dozens of other similar categories of file-upload vulnerabilities.
See also: Drupal websites are vulnerable to double-extension attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Why it matters for the Greek market
Joomla remains one of the most popular CMS in Greece, especially in public organizations, municipalities, educational institutions and small and medium-sized enterprises. Many Greek public sector sites use iCagenda or similar event calendar extensions to display events. The widespread active exploitation of this particular iCagenda vulnerability worldwide makes it imperative to immediately upgrade all installations.
Delay is not just a technical choice — it is a regulatory obligation. Under the new NIS2, critical infrastructure operators and medium/large enterprises are required to apply security patches within a reasonable time of their publication. A Joomla site that is compromised due to a known unapplied update can lead to regulatory consequences, in addition to damage to its reputation and user data.
