HIGHVulnerability
Verified
Global

CISA KEV: iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Analysis

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-10. Remediation due: 2026-07-13.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48939
Source Attribution

Originally published by CISA KEV on Jul 10, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-92966 — The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordP...

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit

CVE-2026-92966
NIST NVD
HIGHVulnerability

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask

The Hacker News
CRITICALVulnerability

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler

The Hacker News