• News/
  • bleepingcomputer-20260713152016

CISA warns of actively exploited RCE flaws in Joomla extensions

BleepingComputer
·
Bill Toulas
·
Published Jul 13, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. The agency has categorized the flaws as a maximum priority, ordering federal agencies to apply available security updates and/or mitigations within three days, with the deadline set for today. The first flaw, tracked as CVE-2026-48939, is an arbitrary file upload flaw impacting the iCagenda extension used for registering and scheduling events and creating calendars. An attacker can exploit the vulnerability to upload arbitrary files to the web server, including PHP scripts, which can lead to data theft, web shell installation, and complete website compromise by achieving remote code execution (RCE). “iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution,” CISA warns in its entry in the Known Exploited Vulnerabilities (KEV) catalog. The second flaw added to KEV is CVE-2026-56291, an arbitrary file upload issue in the Balbooa Forms extension for Joomla. Balbooa Forms is a drag-and-drop form builder for creating contact forms on Joomla sites, with file upload support. According to CISA, this functionality can be used to upload dangerous file types, such as executable files, leading to ...

Read full article

Affected Software

2 affected components
iCagenda (for Joomla) iCagenda extension=4.0.8, =3.9.15
Balbooa Balbooa Forms extension for Joomla=2.4.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are being exploited in Joomla extensions according to the article?

The article discusses vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla.

2

What type of attacks are taking place against these Joomla extensions?

Attackers are exploiting these vulnerabilities to achieve remote code execution through arbitrary file uploads.

3

How does CISA categorize the severity of these flaws?

CISA has categorized the flaws as a maximum priority due to their potential impact.

4

When were these vulnerabilities first published and listed by CISA?

The vulnerabilities were published on July 13, 2026, and are listed as KEV on July 14, 2026.

5

Which Joomla extensions are specifically mentioned as being affected by these remote code execution flaws?

The affected extensions specifically mentioned are iCagenda and Balbooa Forms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203