CISA added two Joomla extension vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after reports of active zero-day abuse against public-facing sites. The flaws, CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms, are unrestricted file upload bugs that let attackers upload executable PHP files and gain remote code execution; the iCagenda issue carries a CVSS 10.0 rating. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were ordered to remediate both issues by July 13, 2026.
Reporting cited by CISA said automated exploitation of the iCagenda flaw began on June 15, while the Balbooa Forms bug was identified during a live customer attack on July 8. Vendors have released fixes, with JoomliC patching iCagenda in versions 4.0.8 and 3.9.15, and Balbooa Forms addressing its vulnerability in version 2.4.1. The warning comes amid broader alerts, including from Australia’s ACSC, about global campaigns targeting CMS platforms and plugins to plant web shells, and CISA urged organizations beyond the federal government to review the KEV catalog and remediate affected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
JoomliC patched the iCagenda vulnerability in versions 4.0.8 and 3.9.15, and Balbooa fixed the Forms vulnerability in version 2.4.1. These updates addressed the unrestricted file upload flaws being exploited against Joomla sites.
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The agency required Federal Civilian Executive Branch agencies to remediate the vulnerabilities under Binding Operational Directive 22-01.
mySites.guru said it discovered CVE-2026-56291 in the Joomla Balbooa Forms extension on July 8, 2026, while responding to a live attack on a customer. The vulnerability is an unrestricted file upload issue that can enable remote code execution.
mySites.guru reported that CVE-2026-48939 in the Joomla iCagenda extension had been under automated exploitation in the wild since June 15, 2026. The flaw is an unrestricted file upload vulnerability that can lead to PHP code execution and remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcetheregister.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcethreataft.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.