INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
iCagenda and Balbooa Forms Exploit Vulnerabilities
| 2026-07-13 05:36 CRITICAL HIGHExecutive Summary AI-generated
The Australian Cyber Security Centre (ACSC) has issued an alert warning of a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. The vulnerabilities, rated 10.0 on the CVSS scoring system, allow arbitrary file upload via the file attachment feature in Joomla extensions like iCagenda and Balbooa Forms. These flaws impact various versions up to and including 4.x of these CMS software, with specific versions being affected by CVE-2026-48939 and CVE-2026-56291. The vulnerabilities have been patched in version 2.4.1, but the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation in the wild.
Technical Mitigations AI-generated
* Regularly update and patch Joomla: Ensure that the iCagenda and Balbooa extensions for Joomla are updated to the latest versions, as well as any other plugins or modules installed on the site. This will help prevent exploitation of known vulnerabilities.
* Use a web application firewall (WAF): Consider installing a WAF such as ModSecurity or Apache mod_security to protect against common web attacks like SQL injection and cross-site scripting (XSS).
* Implement secure file uploads: Use a secure file upload mechanism, such as the Joomla built-in "Uploads" folder's security settings, to prevent unauthorized access to sensitive files.
* Monitor for suspicious activity: Regularly audit the site for suspicious activity, including unusual login attempts or changes in user permissions. This can help identify potential security breaches before they become a problem.
* Use secure protocols (HTTPS): Ensure that all communication between the client's web browser and the Joomla server is encrypted using HTTPS (SSL/TLS).
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Targeting VulnerableCampaign Targeting Vulnerable
CVE-2026-56291CVE-2026-56291
CVE-2026-48939CVE-2026-48939
Target & Sectors
FIVE_EYES
FIVE_EYES
Incident Timeline
June 15, 2026
Threat actors exploited CVE-2026-48939 as a zero-day in automated attacks targeting Joomla sites on which Balbooa Forms is installed.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-48939
According to mySites.guru, a cloud-based dashboard service for managing WordPress and Joomla websites, CVE-2026-48939 is said to have been exploited as a zero-day since June 15, 2026, in automated attacks aimed at Joomla sites on which iCagenda is installed.
organisation
WordPress
According to mySites.guru, a cloud-based dashboard service for managing WordPress and Joomla websites, CVE-2026-48939 is said to have been exploited as a zero-day since June 15, 2026, in automated attacks aimed at Joomla sites on which iCagenda is installed.
infrastructure
2.4.0
MySites.guru said it also observed zero-day exploitation of CVE-2026-56291, which affects Balbooa Forms versions up to and including 2.4.0.
"Up to and including version 2.4.0, its frontend attachment upload had a serious flaw: it accepted a file from any anonymous visitor, with no login, no CSRF token, and no check on the file type," it
said
.
organisation
Balbooa Forms
MySites.guru said it also observed zero-day exploitation of CVE-2026-56291, which affects Balbooa Forms versions up to and including 2.4.0.
infrastructure
4.0.7
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
infrastructure
3.2.1
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
infrastructure
3.9.14
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
infrastructure
4.0.8
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
infrastructure
3.9.15
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
infrastructure
2.4.1
It has been
patched
in version 2.4.1.
July 8, 2026
Threat actors exploited a reported vulnerability in iCagenda and Balbooa Forms as zero-days.
Jul 13, 2026
Threat actors exploited a reported vulnerability in Balbooa Forms for Joomla, allowing them to upload arbitrary files and execute PHP code via the file attachment feature.
Click on any entity below to view its context and source!
organisation
CVSS
The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below -
CVE-2026-48939
- A vulnerability in the iCagenda extension for Joomla that allows the upload of arbitrary files via the file attachment feature, leading to PHP code upload and execution.
organisation
PHP
The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below -
CVE-2026-48939
- A vulnerability in the iCagenda extension for Joomla that allows the upload of arbitrary files via the file attachment feature, leading to PHP code upload and execution.
organisation
CVE-2026-56291
-
CVE-2026-56291
- A vulnerability in the Balbooa Forms extension for Joomla that allows the upload of arbitrary files, leading to remote code execution.
organisation
Balbooa
CVE-2026-56291
- A vulnerability in the Balbooa Forms extension for Joomla that allows the upload of arbitrary files, leading to remote code execution.
July 13, 2026
Threat actors exploited a reported vulnerability in the Balbooa Forms upload folder of iCagenda and Balbooa forms Joomla, targeting zero-day exploits.
Click on any entity below to view its context and source!
attribution
Federal Civilian Executive Branch
It has shared the following indicators of compromise -
Look in the Balbooa Forms upload folder (by default "images/baforms/uploads") for any file that is not an image or document, especially anything ending in PHP
Check the Joomla user list for suspicious administrator accounts
Audit the set for recently modified or unfamiliar PHP files across the site
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have until July 13, 2026, to implement the fixes in their networks.
attribution
FCEB
It has shared the following indicators of compromise -
Look in the Balbooa Forms upload folder (by default "images/baforms/uploads") for any file that is not an image or document, especially anything ending in PHP
Check the Joomla user list for suspicious administrator accounts
Audit the set for recently modified or unfamiliar PHP files across the site
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have until July 13, 2026, to implement the fixes in their networks.
organisation
the Australian Cyber Security Centre
Australia Warns of Global Campaign Targeting Vulnerable CMS Systems
The disclosure comes as the Australian Cyber Security Centre (ACSC) issued an alert warning of a global exploitation campaign targeting various vulnerabilities in content management systems (CMS) and plugins.
organisation
CMS
Australia Warns of Global Campaign Targeting Vulnerable CMS Systems
The disclosure comes as the Australian Cyber Security Centre (ACSC) issued an alert warning of a global exploitation campaign targeting various vulnerabilities in content management systems (CMS) and plugins.
2026/07/13
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two maximum-severity security flaws, CVE-2026-48939 and CVE-2026-56291, to its Known Exploited Vulnerabilities catalog due to reports of zero-day exploitation in the wild for iCagenda and Balbooa Forms Joomla extensions.
Click on any entity below to view its context and source!
organisation
CVSS
The flaws added to the catalog are:
CVE-2026-48939
(CVSS score of 10.0) iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda is an open-source event management extension for Joomla.
organisation
Balbooa
The flaws added to the catalog are:
CVE-2026-48939
(CVSS score of 10.0) iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda is an open-source event management extension for Joomla.
organisation
iCagenda
The flaws added to the catalog are:
CVE-2026-48939
(CVSS score of 10.0) iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda is an open-source event management extension for Joomla.
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days.
organisation
iCagenda Unrestricted Upload of File
The flaws added to the catalog are:
CVE-2026-48939
(CVSS score of 10.0) iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda is an open-source event management extension for Joomla.
organisation
PHP
The vulnerability CVE-2026-48939 allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
organisation
Balbooa Forms
The second flaw added to the catalog, tracked as CVE-2026-56291, is an unauthenticated arbitrary file upload in Balbooa Forms that allows uploading executable files and leads to full RCE.
organisation
RCE
The second flaw added to the catalog, tracked as CVE-2026-56291, is an unauthenticated arbitrary file upload in Balbooa Forms that allows uploading executable files and leads to full RCE.
organisation
Balbooa Forms Joomla Flaws Reportedly Exploited
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days.
Tactical Metrics
Metrics
infrastructure
4.0.7
Software Version
Click for context!
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
Metrics
infrastructure
3.2.1
Software Version
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
Metrics
infrastructure
3.9.14
Software Version
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
Metrics
infrastructure
4.0.8
Software Version
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
Metrics
infrastructure
3.9.15
Software Version
The flaw impacts the following versions -
4.x versions up to and including 4.0.7
Legacy 3.x versions from 3.2.1 up to and including 3.9.14
JoomliC has since
released updates
to address the issue in iCagenda versions 4.0.8 and 3.9.15.
Metrics
infrastructure
2.4.0
Software Version
MySites.guru said it also observed zero-day exploitation of CVE-2026-56291, which affects Balbooa Forms versions up to and including 2.4.0.
"Up to and including version 2.4.0, its frontend attachment upload had a serious flaw: it accepted a file from any anonymous visitor, with no login, no CSRF token, and no check on the file type," it
said
.
Metrics
infrastructure
2.4.1
Software Version
It has been
patched
in version 2.4.1.
Intelligence Sources
Security Affairs
2026-07-11
The Hacker News
2026-07-13
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-04T12:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
the Australian Cyber Security Centre
entity
11x
attribution
Attributing Entity
Vulnerability / Web Security
authority
7x
timeline
Temporal Reference
Jul 13, 2026
date
7x
infrastructure
Software Version
4.0.7
version
2x
vulnerability
Exploited CVE
CVE-2026-48939
cve
Contextual Telemetry
Context Block
7 METRICS
target region
Target Country
Australia
country
campaign
Campaign
Campaign Targeting Vulnerable
operation
general metric
A
48,939
a
tactic
Cyber Operation Type
Remote Code Execution
tactic
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Jul
13
jul
vulnerability
CVSS Score
10
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.