The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. The agency has categorized the flaws as a maximum priority, ordering federal agencies to apply available security updates and/or mitigations within three days, with the deadline set for today. The first flaw, tracked as CVE-2026-48939, is an arbitrary file upload flaw impacting the iCagenda extension used for registering and scheduling events and creating calendars. An attacker can exploit the vulnerability to upload arbitrary files to the web server, including PHP scripts, which can lead to data theft, web shell installation, and complete website compromise by achieving remote code execution (RCE). “iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution,” CISA warns in its entry in the Known Exploited Vulnerabilities (KEV) catalog. The second flaw added to KEV is CVE-2026-56291, an arbitrary file upload issue in the Balbooa Forms extension for Joomla. Balbooa Forms is a drag-and-drop form builder for creating contact forms on Joomla sites, with file upload support. According to CISA, this functionality can be used to upload dangerous file types, such as executable files, leading to ...
CISA warns of actively exploited RCE flaws in Joomla extensions
BleepingComputer
·Bill Toulas
·Published Jul 13, 2026
·Updated
Affected Software
2 affected components
iCagenda (for Joomla) iCagenda extension=4.0.8, =3.9.15
Balbooa Balbooa Forms extension for Joomla=2.4.1
Frequently Asked Questions
1
What vulnerabilities are being exploited in Joomla extensions according to the article?
The article discusses vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla.
2
What type of attacks are taking place against these Joomla extensions?
Attackers are exploiting these vulnerabilities to achieve remote code execution through arbitrary file uploads.
3
How does CISA categorize the severity of these flaws?
CISA has categorized the flaws as a maximum priority due to their potential impact.
4
When were these vulnerabilities first published and listed by CISA?
The vulnerabilities were published on July 13, 2026, and are listed as KEV on July 14, 2026.
5
Which Joomla extensions are specifically mentioned as being affected by these remote code execution flaws?
The affected extensions specifically mentioned are iCagenda and Balbooa Forms.