Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file upload and code execution. The affected extensions are iCagenda and Balbooa Forms, both rated 10.0 CVSS. The exposed attack path can lead to PHP code execution or unauthenticated remote code execution on internet-facing sites.
Related Happenings
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
How related:
The agency has categorized the flaws as a maximum priority, ordering federal agencies to apply available security updates and/or mitigations within three days, with the deadline set for today.
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionHow related: The agency has categorized the flaws as a maximum priority, ordering federal agencies to apply available security updates and/or mitigations within three days, with the deadline set for today.
About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation Wave
H score42
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
How related:
According to website management and security platform mySites.guru, both flaws were exploited in automated attacks before vendors released a patch.
About this happening:
Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation WaveHow related: According to website management and security platform mySites.guru, both flaws were exploited in automated attacks before vendors released a patch.
About this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
WP-SHELLSTORM webshell access brokerage campaign
Campaign
H score71
First: 10.07.2026 14:30
Last: 10.07.2026 14:30
Sources 1
About this happening:
The WP-SHELLSTORM campaign exposed its own infrastructure, revealing a webshell access brokerage that targeted WordPress and Joomla sites at scale and backdoored *...
WP-SHELLSTORM webshell access brokerage campaign
CampaignAbout this happening: The WP-SHELLSTORM campaign exposed its own infrastructure, revealing a webshell access brokerage that targeted WordPress and Joomla sites at scale and backdoored *...
CISA KEV remediation order for CVE-2026-48907
Public Sector Action
H score89
First: 17.06.2026 08:50
Last: 17.06.2026 08:50
Sources 1
About this happening:
CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
CISA KEV remediation order for CVE-2026-48907
Public Sector ActionAbout this happening: CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
Widget Factory Joomla Content Editor JCE actively exploited improper access control security flaw (CVE-2026-48907)
Vulnerability
H score89
First: 17.06.2026 08:50
Last: 17.06.2026 08:50
Sources 1
About this happening:
The Widget Factory Joomla Content Editor (JCE) flaw CVE-2026-48907 has been added to CISA's KEV catalog after evidence of active exploitation, putting affected Joo...
Widget Factory Joomla Content Editor JCE actively exploited improper access control security flaw (CVE-2026-48907)
VulnerabilityAbout this happening: The Widget Factory Joomla Content Editor (JCE) flaw CVE-2026-48907 has been added to CISA's KEV catalog after evidence of active exploitation, putting affected Joo...
Timeline
-
13.07.2026 08:36 1 articles · 13d ago
Automated attacks exploit iCagenda file attachment flaw
Exploitation ObservedOn June 15, 2026, automated attacks against Joomla sites with iCagenda installed began exploiting CVE-2026-48939 as a zero-day, abusing the Submit an Event file attachment feature to upload malicious files that can lead to PHP code execution and planted shells under images/icagenda/frontend/attachments/.
Show sources
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — thehackernews.com — 13.07.2026 08:36
-
13.07.2026 08:36 1 articles · 13d ago
mySites.guru discovers Balbooa Forms zero-day after live attack
Technical Analysis UpdateOn July 8, 2026, mySites.guru discovered CVE-2026-56291 after a live attack on one of its customers, finding that Balbooa Forms versions up to and including 2.4.0 accepted anonymous frontend attachment uploads with no login, no CSRF token, and no file-type check, enabling arbitrary file upload and unauthenticated remote code execution; the patched version is 2.4.1.
Show sources
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — thehackernews.com — 13.07.2026 08:36
-
13.07.2026 08:36 3 articles · 13d ago
CISA adds Joomla extension flaws to KEV catalog
Legal Policy Action UpdateOn July 13, 2026, CISA added CVE-2026-48939 and CVE-2026-56291 to the Known Exploited Vulnerabilities (KEV) catalog after reports of zero-day exploitation in the wild, while Federal Civilian Executive Branch agencies were ordered to implement fixes by July 13, 2026; the Australian Cyber Security Centre also warned that a global campaign is scanning CMS software and plugins to deploy web shells.
Show sources
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — thehackernews.com — 13.07.2026 08:36
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — thehackernews.com — 13.07.2026 08:36
- CISA warns of actively exploited RCE flaws in Joomla extensions — www.bleepingcomputer.com — 13.07.2026 18:20