Wire · regulatory
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 13 July 2026 · Fusion42 review
CISA has added two maximum-severity zero-day vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities catalogue; both allow arbitrary file upload and remote code execution on Joomla sites, with iCagenda being actively exploited since June 2026.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
If you run a Joomla site with iCagenda or Balbooa Forms, you are currently being scanned by automated attackers; patch immediately or remove the plugins—CISA has marked these as actively exploited in the wild.
◆ Coverage
1 source · 13 Jul 2026
◆ Related on Wire
◆ Topics