HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Vulnerabilities & update guides
New htprotect.app - Centralized Joomla Site Management for Multiple Websites
Security vulnerability

SP Page Builder – critical RCE zero-day, actively exploited

Critical Actively exploitedCVE: Not stated in the source article
Act now
Update SP Page Builder to 6.8.0 immediately – the zero-day is being actively exploited.

Secure version: SP Page Builder 6.8.0 - 6.6.2 is no longer enough · via JoomShaper (account required)

At a glance

Affected extension
SP Page Builder – page builder, component com_sppagebuilder
Type of flaw
Unauthenticated file upload (the asset.uploadCustomIcon function checked neither login nor file type) → Remote Code Execution (RCE)
Affected versions
All versions up to and including 6.7.1 (two flaws: file upload up to 6.6.1, SQL injection up to 6.7.1)
Secure version
SP Page Builder 6.8.0 - 6.6.2 is no longer enough   Download
Severity
Critical · actively exploited
CVE
Not stated in the source article
Joomla compatibility
Joomla 4 / 5 / 6
Status / published
As of: 16 June 2026

What is this about?

SP Page Builder by JoomShaper is one of the most widespread page builders for Joomla. The asset.uploadCustomIcon function checked neither a login nor the file type. This allowed malware to be uploaded and executed without a login (Remote Code Execution).

Affected is the entire 6.x series up to and including 6.7.1. Alongside the file upload, a second and different flaw appeared: an SQL injection without a login through the “load more” endpoint (CVE-2026-65876) that allowed the database to be read. The earlier emergency update 6.6.2 only closed the upload; only 6.8.0 is safe. It is classified as a critical zero-day and is already being actively exploited.

Typical traces of an attack: hidden super-user accounts (e.g. with email addresses ending in @secure.local) and several PHP backdoors. The update only closes the front door – existing access remains until it is removed. Merely disabling the extension does not help.

Am I affected? – How to check

  1. Open the back end

    Log in to the Joomla administrator.

  2. Check the version

    Open Extensions›Manage›Manage and filter for "SP Page Builder".

  3. Assess the version

    If the version is 6.7.1 or below, the site is vulnerable. Only 6.8.0 is secure.

  4. Check for signs of intrusion

    Look for super-users with the address @secure.local and for foreign .php files (among others under images/…/fonts/ and users.php in /media/).

How to fix it

Before any update: back up
Back up your files and database before updating – so you can roll back if anything goes wrong (e.g. via Akeeba Backup or your host).
  1. Open the Update center

    Go to System›Update›Extensions and click Check for updates.

  2. Update SP Page Builder

    Select the entry and update to 6.8.0 or newer.

  3. Verify the version

    Confirm that at least 6.8.0 is now installed.

Manual installation (alternative)
Alternatively, download the package from joomshaper.com and install it via Extensions›Manage›Install. Important: do not restore old files.

Official source: via JoomShaper (account required). Make sure you have at least SP Page Builder 6.8.0 - 6.6.2 is no longer enough.

Has the site already been attacked?

Actively exploited – an update alone is not enough
The flaw leaves behind hidden super-user accounts and several PHP backdoors. Remove these specifically, change all passwords and harden the upload folders (e.g. via .htaccess that blocks PHP execution there). Merely disabling the extension does not help.

Need help with the clean-up? Find qualified specialists in the Joomla Service Providers Directory.

Sources & further reading

The official information from the respective vendor always takes precedence. This page neutrally summarises publicly available information.

Related vulnerabilities

Other extensions with comparable weaknesses. Check whether any of them is installed on your site.

Helix3 FrameworkCriticalactively exploited
JoomShaperLearn more
Helix UltimateCritical
JoomShaperLearn more
Astroid FrameworkCriticalactively exploited
TemPlazaLearn more
Supporters

Supporters of this site

htprotect.org is a free, vendor-independent information service. It is supported by:

Host & community
FC-Hosting

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.

fc-hosting.de
Initiator & operator
Website-Bereinigung.de

Specialised in cleaning, maintaining and securing Joomla and WordPress websites.

website-bereinigung.de

Support this project

You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.

Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.

Support HTProtect now
Bauschild & Service

Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.

bauschildundservice.de
IT Specialista

Professional IT support from Czechia – Windows management, domain administration and web hosting.

defendersoft.cz
onlineweg.de

Travel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.

onlineweg.de
Criadero

Creative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.

criadero.de
Jahn EDV-Dienst GmbH

IT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.

jahnedv.de
IsariConsult

Information-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.

isari-consult.de
Schippelbein Mediengestaltung

Media design from Friedrichshafen – Joomla and WordPress sites, online shops, graphics and 3D.

schippelbein.com