Lyrie
Active Exploitation
1 sources verified·1 min read
By Lyrie Threat Intelligence·6/25/2026

0day Intel: 🚨 CVE-2026-48908 (CVSS 10.0)

A critical flaw in Joomla's SP Page Builder can e

Source: X search for CVE-2026 critical

Posted: 2026-06-24T15:43:55.000Z

Likes: 72

Full Tweet

🚨 CVE-2026-48908 (CVSS 10.0)

A critical flaw in Joomla's SP Page Builder can enable unauthenticated file upload and potential RCE:

▪️Versions 1.0.0–6.6.1 affected

▪️Active exploitation reported

▪️Patched in 6.6.2

Censys observed 194,793 web properties loading the component. https://t.co/wob1xFAEqp

Source Link

https://x.com/i/status/2069808747484963270

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]@3566263693 on X