CVE-2026-48939: iCagenda Unrestricted File Upload Leads to RCE in Joomla (KEV, Active Exploitation)
CVE-2026-48939 is a KEV-listed unrestricted file upload flaw in Joomla's iCagenda component enabling web shell uploads and RCE; our detection covers the exploitation pattern across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.