iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

A critical flaw has been discovered in Joomla, one of the most widely used content management systems (CMS) on the web. The vulnerability, dubbed “iCagenda and Balbooa Forms,” has allegedly been exploited as a zero-day exploit by malicious actors. This means that hackers have already begun taking advantage of the weakness before it was publicly disclosed, putting thousands of websites at risk.

The flaw is related to Joomla’s Balbooa Forms plugin, which allows users to create dynamic forms on their sites. According to reports, the vulnerability can be exploited through a specially crafted form submission, allowing an attacker to execute arbitrary code on the affected site. This could potentially lead to a range of malicious activities, including data theft and website takeover.

The iCagenda and Balbooa Forms flaw is particularly worrying because it has been discovered using artificial intelligence (AI) models specifically designed for vulnerability detection. These AI-powered tools are increasingly being used by cybersecurity researchers and hackers alike, making them a double-edged sword in the world of cybersecurity. On one hand, they can quickly identify and exploit vulnerabilities; on the other, they can also help to discover and fix these weaknesses before they’re exploited.

Joomla’s popularity makes it a prime target for attackers looking to compromise websites. With over 3 million sites running Joomla worldwide, even a small percentage of affected users translates into thousands of potential targets. The fact that this flaw has already been exploited as a zero-day means that many of these sites may have already fallen victim to the attack.

The discovery of the iCagenda and Balbooa Forms vulnerability highlights the importance of keeping software up-to-date, particularly for widely used CMS platforms like Joomla. While it’s impossible to prevent all vulnerabilities from being discovered, using AI-powered tools to scan for weaknesses can help organizations stay ahead of potential threats. By adopting a proactive approach to cybersecurity and regularly updating their software, site administrators can significantly reduce the risk of falling victim to exploits like this.

For those running Joomla sites, it’s essential to take immediate action to secure your website. This includes applying the latest patches from Joomla and ensuring that all plugins, including Balbooa Forms, are updated to the latest versions. Additionally, users should consider implementing a web application firewall (WAF) to provide an extra layer of protection against potential attacks. By taking these precautions, site administrators can minimize their exposure to the iCagenda and Balbooa Forms vulnerability and other similar threats.


Source: The Hacker News — 2026-07-13