CVE Tools

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

The Hacker NewsBy The Hacker News

Reported exploitedBalbooa FormsiCagenda

Our summary

CISA has added two high-severity vulnerabilities affecting the iCagenda and Balbooa Forms extensions for Joomla to its catalog of known exploited vulnerabilities, after reports confirmed they were being actively exploited as zero-days. CVE-2026-48939 in iCagenda enables arbitrary file uploads leading to remote code execution, while CVE-2026-56291 in Balbooa Forms allows unauthenticated attackers to upload malicious PHP files. Both flaws have been addressed in updated versions—4.0.8 and 3.9.15 for iCagenda, and 2.4.1 for Balbooa Forms. Administrators are urged to update immediately and scan for suspicious files on their systems.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store