CISA warns of actively exploited RCE flaws in Joomla extensions

Cybersecurity watchdog CISA has issued a high-priority warning about two vulnerabilities in widely-used Joomla extensions that are being actively exploited by attackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges federal agencies to apply security updates within three days, as hackers are taking advantage of arbitrary file upload flaws in the iCagenda and Balbooa Forms extensions to gain remote code execution.

The vulnerabilities, tracked as CVE-2026-48939 and CVE-2026-56291, allow attackers to upload malicious files to a Joomla website’s server, including PHP scripts that can execute arbitrary code. This can lead to data theft, web shell installation, and complete website compromise. The CISA has categorized these flaws as maximum priority, emphasizing the need for swift action.

The iCagenda extension is used for event registration and calendar creation, while Balbooa Forms is a drag-and-drop form builder for creating contact forms on Joomla sites. Both extensions contain file upload functionality that can be exploited to upload malicious files, resulting in RCE. According to CISA, attackers began exploiting these flaws before vendors released patches.

The management service mySites.guru notes that the CVE-2026-48939 vulnerability was discovered just hours before the release of iCagenda version 4.0.8, which fixed the issue. Similarly, the CVE-2026-56291 flaw in Balbooa Forms was exploited as a zero-day vulnerability, with attacks beginning on July 8 – a day before the vendor released a fix.

The CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and urges website administrators managing Joomla sites to check for the presence of iCagenda and Balbooa Forms. If affected, they should take immediate action to protect their assets by applying available security updates and/or mitigations.

Website owners can check if their sites are using the affected extensions by logging into their Joomla control panel. They can then verify if version 4.0.8 or 3.9.15 of iCagenda is installed, or version 2.4.1 of Balbooa Forms. If not, they should update to the latest versions as soon as possible.

In light of this warning, security teams should conduct regular vulnerability scans and penetration testing to identify potential weaknesses in their systems. By staying vigilant and proactive, businesses can minimize the risk of falling victim to these types of attacks and protect their assets from potential compromise.


Source: Bleeping Computer — 2026-07-13