The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active zero-day exploitation. Both flaws are rated 10.0 on the CVSS scoring system.
- CVE-2026-48939: Affects iCagenda extension for Joomla, allowing arbitrary file upload via the file attachment feature, leading to PHP code upload and execution. Exploited as a zero-day since June 15, 2026, in automated attacks targeting Joomla sites. Patched in versions 4.0.8 and 3.9.15.
- CVE-2026-56291: Affects Balbooa Forms extension for Joomla, allowing unauthenticated remote code execution via arbitrary file upload. Patched in version 2.4.1.
According to mySites.guru, a cloud-based dashboard service, the iCagenda flaw was first observed in a client’s access log, with an automated scanner identifying itself as ‘icagenda-batch/1.0’ uploading a malicious file and fetching a planted shell. The Balbooa Forms vulnerability was discovered on July 8, 2026, following a live attack on a customer. Indicators of compromise include suspicious PHP files in the upload folders and unauthorized administrator accounts.
Federal Civilian Executive Branch (FCEB) agencies must apply fixes by July 13, 2026. Separately, the Australian Cyber Security Centre (ACSC) warned of a global exploitation campaign targeting multiple CMS vulnerabilities, including those in Sneeit Framework, WPBookit, Gravity Forms, Craft CMS, Ninja Forms, MaxSite CMS, Breeze Cache, WavePlayer, MetInfo CMS, and Joomla JCE. The campaign involves deploying web shells for remote access, with AI accelerating the speed and scale of exploitation.
CVEs: CVE-2026-48939, CVE-2026-56291, CVE-2025-6389, CVE-2025-7852, CVE-2025-12352, CVE-2025-32432, CVE-2026-0740, CVE-2026-3395, CVE-2026-3844, CVE-2025-12057, CVE-2026-29014, CVE-2026-48907
Companies: CISA, ACSC, mySites.guru, JoomliC
Products: iCagenda, Balbooa Forms, Joomla, Sneeit Framework, WPBookit, Gravity Forms, Craft CMS, Ninja Forms, MaxSite CMS, Breeze Cache, WavePlayer, MetInfo CMS
Original source: thehackernews.com