Zero-Day Exploits Target Joomla Extensions: iCagenda and Balbooa Forms (2026)

The recent addition of two critical vulnerabilities to the CISA's Known Exploited Vulnerabilities (KEV) catalog has brought attention to the security risks associated with iCagenda and Balbooa extensions for Joomla. These vulnerabilities, both rated 10.0 on the CVSS scoring system, highlight the importance of proactive security measures and the need for users to stay vigilant. The first vulnerability, CVE-2026-48939, allows for the upload of arbitrary files via the file attachment feature in the iCagenda extension, leading to PHP code upload and execution. This flaw has been actively exploited as a zero-day since June 15, 2026, in automated attacks targeting Joomla sites with iCagenda installed. The issue impacts versions 4.x up to 4.0.7 and legacy 3.x versions from 3.2.1 to 3.9.14. JoomliC has released updates to address this vulnerability in versions 4.0.8 and 3.9.15, and site owners are advised to check for and remove any suspicious PHP files in the specified folder. The second vulnerability, CVE-2026-56291, affects Balbooa Forms versions up to 2.4.0 and allows unauthenticated file upload, leading to remote code execution. This flaw was discovered on July 8, 2026, and has been patched in version 2.4.1. Indicators of compromise include checking the Balbooa Forms upload folder for non-image or document files, especially those ending in PHP, and auditing the Joomla user list for suspicious administrator accounts. The timing of these disclosures is significant, as Federal Civilian Executive Branch (FCEB) agencies have until July 13, 2026, to implement the necessary fixes in their networks. These vulnerabilities are part of a broader global campaign targeting various content management systems (CMS) and plugins, as warned by the Australian Cyber Security Centre (ACSC). The campaign involves malicious actors scanning websites for opportunities to deploy web shells, leveraging vulnerabilities that allow unauthenticated file upload, remote code execution, server-side request forgery, or deserialization. The ACSC emphasizes the rapidly evolving cyber risk landscape, noting that advances in AI are accelerating the speed and scale of cyber operations, reducing the time between vulnerability disclosure and exploitation. This highlights the need for organizations to stay proactive in their security measures and to address vulnerabilities promptly to mitigate the risk of exploitation.

Zero-Day Exploits Target Joomla Extensions: iCagenda and Balbooa Forms (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rob Wisoky

Last Updated:

Views: 5382

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.