CISA warns of actively exploited RCE flaws in Joomla extensions

Cybersecurity experts are sounding the alarm over a pair of critical vulnerabilities affecting popular Joomla extensions, iCagenda and Balbooa Forms. These flaws have been actively exploited by attackers, compromising websites and putting sensitive data at risk.

The US Cybersecurity and Infrastructure Security Agency (CISA) has categorized these vulnerabilities as “maximum priority,” urging federal agencies to apply available security updates within a tight three-day deadline. This warning is a stark reminder of the importance of staying on top of software patching and vulnerability management.

At the heart of this issue are arbitrary file upload flaws that allow attackers to upload malicious files, including PHP scripts, to Joomla websites. These vulnerabilities can lead to remote code execution (RCE), which enables hackers to gain full control over a website, install web shells, or steal sensitive data. In other words, if an attacker can inject malicious code into a vulnerable website, they can essentially take control of the entire system.

The iCagenda extension is primarily used for event registration and calendar management, while Balbooa Forms is a drag-and-drop form builder that allows users to create contact forms on Joomla sites with file upload support. The problem lies in these extensions’ ability to upload arbitrary files, which can be exploited by attackers to upload malicious code.

According to CISA, both vulnerabilities have been actively exploited in automated attacks before patches were released. For iCagenda, attacks were observed just hours before the release of version 4.0.8, which addressed CVE-2026-48939. Similarly, Balbooa Forms’ CVE-2026-56291 vulnerability was exploited as a zero-day vulnerability, used in attacks since July 8.

Website administrators managing Joomla sites should take immediate action to protect their assets. This includes checking for the presence of iCagenda and Balbooa Forms extensions and applying available security updates or patches. The flaws are fixed in iCagenda version 4.0.8 and 3.9.15, released on June 15-16, and Balbooa Forms version 2.4.1, released on July 9.

In the face of such high-profile vulnerabilities, it’s essential for security teams to stay vigilant and proactive in their threat detection efforts. As the Picus whitepaper highlights, many successful attacks go undetected until it’s too late. By regularly testing every layer of their environment and staying up-to-date with software patches, organizations can significantly reduce their attack surface and prevent costly breaches.

To protect your Joomla site, take a proactive approach to patch management and vulnerability scanning. Regularly update extensions like iCagenda and Balbooa Forms, and implement robust security measures to detect and respond to potential threats. Remember, it’s always better to test every layer before attackers do.


Source: Bleeping Computer — 2026-07-13