CVE Tools

CISA warns of actively exploited RCE flaws in Joomla extensions

BleepingComputerBy Bill Toulas

Reported exploitediCagendaBalbooa Forms

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting two remote code execution (RCE) vulnerabilities in popular Joomla extensions—iCagenda and Balbooa Forms. These flaws allow malicious actors to upload arbitrary files, potentially leading to full website compromise. The vulnerabilities, tracked as CVE-2026-48939 and CVE-2026-56291, were added to CISA's Known Exploited Vulnerabilities catalog with maximum priority, requiring immediate mitigation. Patches are now available for both extensions.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store