CVE-2026-56290
Summary
A remote code execution vulnerability in the Joomla Page Builder extension, added to CISA's Known Exploited Vulnerabilities catalog on 7 July 2026.
Details
The digest recorded it in the 7 July KEV batch with a reported CVSS of 10.0, meaning an unauthenticated route to code execution on a CMS extension that site owners install for layout convenience and rarely review. Joomla's extension ecosystem is the recurring weak point: the core is patched promptly, while third-party builders, forms and calendars carry the exploited flaws — the same pattern as the iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) zero-days recorded a week later. An extension inventory is the prerequisite for defending it.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-56290 |
| CVSS | 9.8 |
| Vendor / product | Joomla (Page Builder) |
| Reported in the digest | 2026-07-09 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-09.md