Critical CVSS 10.0 Vulnerabilities in Joomla SP Page Builder and Page Builder CK Enable One-Click Unauthenticated File Upload and Full Site Takeover
U.S. authorities have warned about three actively exploited vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog, urging immediate patching. The most severe issues, CVE-2026-48908 and CVE-2026-56290, affect Joomla extensions SP Page Builder and Page Builder CK respectively, both scoring 10.0 and allowing unauthenticated attackers to upload and execute arbitrary PHP files for complete site compromise. A third flaw, CVE-2026-55255 (CVSS 9.9), impacts the Langflow AI application platform and permits authenticated attackers to hijack other users’ processes and access sensitive secrets. All three vulnerabilities are already being used in real-world attacks, though CISA has not disclosed attacker identities or victim counts. Federal agencies must remediate under BOD 26-04, while all organizations are advised to check for vulnerable components, apply fixes, and review logs for prior intrusions.
securitylab_n•Vulnerabilities & Exploits