iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
Following reports of zero-day exploitation in the field, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) database with two maximum-severity security holes affecting the iCagenda and Balbooa extensions for Joomla.
The vulnerabilities listed below have both received a CVSS score of 10.0:
CVE-2026-48939 is a vulnerability in the Joomla iCagenda extension that permits arbitrary files to be uploaded using the file attachment feature, resulting in the upload and execution of PHP code.
CVE-2026-56291 is a flaw in the Joomla Balbooa Forms extension that permits the upload of any file, resulting in remote code execution.
MySites.guru, a cloud-based dashboard service for managing WordPress and Joomla websites, claims t...

