INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

iCagenda and Balbooa Forms Exploit Vulnerabilities

| 2026-07-13 05:36 CRITICAL HIGH
Executive Summary AI-generated
The Australian Cyber Security Centre (ACSC) has issued an alert warning of a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. The vulnerabilities, rated 10.0 on the CVSS scoring system, allow arbitrary file upload via the file attachment feature in Joomla extensions like iCagenda and Balbooa Forms. These flaws impact various versions up to and including 4.x of these CMS software, with specific versions being affected by CVE-2026-48939 and CVE-2026-56291. The vulnerabilities have been patched in version 2.4.1, but the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation in the wild.
Technical Mitigations AI-generated
* Regularly update and patch Joomla: Ensure that the iCagenda and Balbooa extensions for Joomla are updated to the latest versions, as well as any other plugins or modules installed on the site. This will help prevent exploitation of known vulnerabilities. * Use a web application firewall (WAF): Consider installing a WAF such as ModSecurity or Apache mod_security to protect against common web attacks like SQL injection and cross-site scripting (XSS). * Implement secure file uploads: Use a secure file upload mechanism, such as the Joomla built-in "Uploads" folder's security settings, to prevent unauthorized access to sensitive files. * Monitor for suspicious activity: Regularly audit the site for suspicious activity, including unusual login attempts or changes in user permissions. This can help identify potential security breaches before they become a problem. * Use secure protocols (HTTPS): Ensure that all communication between the client's web browser and the Joomla server is encrypted using HTTPS (SSL/TLS).
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Targeting VulnerableCampaign Targeting Vulnerable CVE-2026-56291CVE-2026-56291 CVE-2026-48939CVE-2026-48939
Target & Sectors
FIVE_EYES FIVE_EYES
Incident Timeline
‎June 15, 2026
Threat actors exploited CVE-2026-48939 as a zero-day in automated attacks targeting Joomla sites on which Balbooa Forms is installed.
vulnerability CVE-2026-48939
organisation WordPress
infrastructure 2.4.0
organisation Balbooa Forms
infrastructure 4.0.7
infrastructure 3.2.1
infrastructure 3.9.14
infrastructure 4.0.8
infrastructure 3.9.15
infrastructure 2.4.1
‎July 8, 2026
Threat actors exploited a reported vulnerability in iCagenda and Balbooa Forms as zero-days.
‎Jul 13, 2026
Threat actors exploited a reported vulnerability in Balbooa Forms for Joomla, allowing them to upload arbitrary files and execute PHP code via the file attachment feature.
organisation CVSS
organisation PHP
organisation CVE-2026-56291 -
organisation Balbooa
‎July 13, 2026
Threat actors exploited a reported vulnerability in the Balbooa Forms upload folder of iCagenda and Balbooa forms Joomla, targeting zero-day exploits.
attribution Federal Civilian Executive Branch
attribution FCEB
organisation the Australian Cyber Security Centre
organisation CMS
‎2026/07/13
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two maximum-severity security flaws, CVE-2026-48939 and CVE-2026-56291, to its Known Exploited Vulnerabilities catalog due to reports of zero-day exploitation in the wild for iCagenda and Balbooa Forms Joomla extensions.
organisation CVSS
organisation Balbooa
organisation iCagenda
organisation iCagenda Unrestricted Upload of File
organisation PHP
organisation Balbooa Forms
organisation RCE
organisation Balbooa Forms Joomla Flaws Reportedly Exploited
Tactical Metrics
Metrics
infrastructure
‎4.0.7
Software Version
Metrics
infrastructure
‎3.2.1
Software Version
Metrics
infrastructure
‎3.9.14
Software Version
Metrics
infrastructure
‎4.0.8
Software Version
Metrics
infrastructure
‎3.9.15
Software Version
Metrics
infrastructure
‎2.4.0
Software Version
Metrics
infrastructure
‎2.4.1
Software Version