Finding
indicator:67684:descriptionWhat happened
CISA KEV describes CVE-2026-48939 as: iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.