HIGHVulnerability
Verified
Global

CISA KEV: iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Analysis

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-10. Remediation due: 2026-07-13.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48939
Source Attribution

Originally published by CISA KEV on Jul 10, 2026. Verified by: CISA.

Related Threats