HackMyIP
← Back to News
2026-07-13 The Hacker News

CISA Flags Critical Joomla Zero-Days in iCagenda and Balbooa Forms

Zero-DayVulnerabilityIncident Response

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity flaws affecting Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities (KEV) catalog after confirming active zero-day exploitation in the wild. Both vulnerabilities carry a CVSS score of 10.0 and enable unauthenticated remote code execution through arbitrary file upload weaknesses, placing tens of thousands of Joomla-powered websites at immediate risk.

CVE-2026-48939 resides in iCagenda's "Submit an Event" form functionality, where the file attachment feature fails to properly validate uploads, allowing attackers to plant and execute PHP web shells. According to mySites.guru, automated attacks exploiting this flaw began on June 15, 2026, with a scanner identifying itself as "icagenda-batch/1.0" requesting tokens, posting malicious payloads, and retrieving planted shells from the "images/icagenda/frontend/attachments/" directory. JoomliC has released patches in iCagenda versions 4.0.8 and 3.9.15, and administrators are urged to audit that folder for unauthorized PHP files. Site owners running legacy installations can use the port scanner to identify exposed services that could be leveraged in follow-on attacks.

CVE-2026-56291, discovered by mySites.guru on July 8, 2026 following a live attack on a customer, affects Balbooa Forms versions up to and including 2.4.0. The frontend attachment upload accepted files from any anonymous visitor without authentication, CSRF tokens, or file type checks, enabling unauthenticated remote code execution by simply uploading a PHP file to a public directory. The flaw has been patched in version 2.4.1, and defenders should inspect the default "images/baforms/uploads" folder for non-image files, audit Joomla administrator accounts for suspicious additions, and review recently modified PHP files across the site.

Federal Civilian Executive Branch (FCEB) agencies have until July 13, 2026 to apply the fixes. Given the trivial exploitation and active automated campaigns, Joomla administrators should treat any unpatched instance as compromised and initiate incident response procedures immediately. Operators managing multiple Joomla deployments can use the WHOIS lookup and SSL/TLS checker tools to verify asset inventory and ensure hardened transport security across affected environments.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →