Skip to content
COOEY

EXPOSURES › CVE-2026-48939

CVE-2026-48939

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-48939 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatchedzero-day

iCagenda allows arbitrary file uploads leading to PHP code execution via its attachment feature.

This vulnerability enables attackers to upload malicious PHP files through the file attachment feature, resulting in remote code execution. DIB organizations must ensure iCagenda is patched and verify upload restrictions to prevent unauthorized code execution.

Shame score — The vulnerability allows arbitrary file uploads leading to PHP code execution, which is a significant security risk for systems handling sensitive data.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.