Exploited CVEs / CVE-2026-56290
CVE-2026-56290
Joomlack Page Builder Improper Access Control Vulnerability. Exploitation in the wild is confirmed by CISA, not predicted. Federal agencies were required to remediate by 2026-07-10 (that deadline has passed); treat that date as the outer bound for your own environment. Check the vendor security advisory for the fix.
Risk summary
Actively exploited Joomlack Page Builder vulnerability, Critical severity, CVSS v3 9.8. Added to the CISA KEV catalog 2026-07-07.
Senserva AI Opinion for CVE-2026-56290
This is a real-world exploited flaw in Page Builder CK, the Joomla extension from joomlack.fr, not a generic Joomla core issue. The defect is improper access control that leaves a file upload endpoint reachable without authentication, so an unauthenticated attacker can upload an arbitrary file (such as a PHP web shell) and reach remote code execution on the web server. Reporting places the affected range at Page Builder CK below version 3.6.0, with 3.6.0 as the fixed release. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-07 alongside Adobe and Langflow flaws, which sets a Federal civilian agency remediation deadline and signals confirmed in-the-wild use. With CVSS 9.8 and EPSS at 83 percent, the risk here is not theoretical: any internet-facing Joomla site running this extension below 3.6.0 should be treated as a live target, and a compromise means attacker code execution rather than only data disclosure. No ransomware campaign has been tied to it so far, but web shell footholds are commonly sold or reused, so absence of ransomware attribution is not a reason to defer patching.
Do this: Inventory every Joomla site for the Page Builder CK extension and check its version. If it is below 3.6.0, update to 3.6.0 or later immediately. Because exploitation is unauthenticated and confirmed active, also hunt for compromise on any site that was exposed: review the extension upload and media directories for unexpected PHP or script files, check web server and PHP logs for POST requests to the extension upload handler from unknown sources, and inspect for newly created admin accounts, cron jobs, or scheduled tasks. If you cannot patch at once, block external access to the affected endpoint at the web application firewall or take the site offline. Federal civilian agencies must meet the CISA KEV due date; everyone else should treat that date as the outside limit.
- CISA Adds Three Known Exploited Vulnerabilities to Catalog (2026-07-07): Primary government source that confirms the KEV listing and the remediation timeline for this CVE.
- CCB Belgium advisory: critical unauthenticated arbitrary file upload in Page Builder CK (CVE-2026-56290): National CERT advisory that names the exact extension, the RCE mechanism, and urges immediate patching.
- The Hacker News: CISA Adds Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV: Respected reporter coverage that puts the flaw in context with the other CVEs added the same day.
AI-generated from public data, 2026-07-26. Verify against the vendor advisory before acting.
Senserva AI Opinion and rich prompt for CVE-2026-56290
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
Updated August 19, 2026. Data refreshed on every build from MSRC, CISA KEV, and FIRST EPSS.
Full tracking and change history for CVE-2026-56290
- Published
- 2026-07-07
- Last revised
- 2026-07-07
- Changes tracked
- 1
Published and last-revised dates are authoritative, from Microsoft MSRC (or the CISA KEV date-added). Senserva additionally records day-to-day changes from 2026-07-07, refreshed several times a day; the change count reflects that forward-only tracking.
The strongest signal is CVE-2026-56290's presence in the CISA KEV catalog since 2026-07-07, confirming active exploitation. Severity landed at CVSS 9.8 on 2026-07-17, and EPSS then climbed sharply from 2.9% to 18.7% on 2026-07-23 and to 83.3% on 2026-07-24. Every indicator points upward, so prioritize remediation today.
Drawn by Senserva Vivid from the Senserva change record. Hover any point for its date and value.
- 2026-07-07 added to the CISA KEV catalog by CISA
- 2026-07-17 CVSS 0.0 to 9.8; EPSS first scored at 2.9%
- 2026-07-23 EPSS 2.9% to 18.7%
- 2026-07-24 EPSS 18.7% to 83.3%
Recorded by Senserva on the dates shown, from CISA KEV and FIRST EPSS. This is what moved and when, which neither the vendor advisory nor NVD publishes.
CISA required action
Federal (BOD 22-01) remediation due date: 2026-07-10 (past due).
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Official fix for CVE-2026-56290
Check the vendor's security advisory channel for the patched Page Builder versions and workarounds.
Common questions about CVE-2026-56290
Is CVE-2026-56290 actively exploited?
Yes. CVE-2026-56290 was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026-07-07, which means exploitation in the wild has been confirmed, not predicted. Its EPSS 30-day exploitation probability is 83%.
What is the CISA deadline and required action for CVE-2026-56290?
CISA set the federal (BOD 22-01) remediation due date at 2026-07-10, which has passed; treat any unremediated system as overdue. The verbatim required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
What fixes CVE-2026-56290?
Check the vendor's security advisory for the patched Page Builder versions and any workarounds. KEV listing makes this a fix-first item: patch it ahead of higher-CVSS issues nobody is exploiting.
Can I ask my own AI about CVE-2026-56290?
Yes. This page includes a free, ready-to-paste AI prompt containing CVE-2026-56290's key facts: severity, CVSS, EPSS, the KEV date, the CISA due date, and the required action. Copy it into Claude, ChatGPT, or Copilot; the data is refreshed twice a day (5 AM and 3 PM US Central).
Scope and sources
- Authoritative references
Every actively exploited CVE, searchable with due dates and CSV export: the exploited-CVE tracker. The newest additions: exploited this week.