The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are actively exploiting two critical vulnerabilities in popular Joomla extensions.

Both flaws allow arbitrary file uploads that can lead to remote code execution (RCE). Because the vulnerabilities are already being exploited, CISA has added them to its Known Exploited Vulnerabilities (KEV) catalog and ordered US federal agencies to apply fixes or mitigations within three days.

iCagenda Flaw Allows Remote Code Execution

The first vulnerability, tracked as CVE-2026-48939, affects the iCagenda extension for Joomla.

The extension is widely used to manage calendars, events, and registrations. However, the vulnerable file upload feature allows attackers to upload arbitrary files, including malicious PHP scripts.

As a result, threat actors can install web shells, steal data, and gain complete control of a compromised website.

According to CISA, the flaw stems from unrestricted uploads of dangerous file types, allowing attackers to execute uploaded PHP code on the server.

Balbooa Forms Also Targeted

The second vulnerability, CVE-2026-56291, impacts the Balbooa Forms extension.

Balbooa Forms is a drag-and-drop form builder that supports file uploads. Attackers can abuse this functionality to upload executable files and achieve remote code execution.

Once exploited, the flaw can allow a complete takeover of the affected Joomla website.

Attacks Began Before Security Updates

Security researchers say both vulnerabilities were exploited before patches became available.

According to website management platform mySites.guru, attackers targeted the iCagenda flaw only hours before version 4.0.8 was released.

Meanwhile, the Balbooa Forms vulnerability was reportedly exploited as a zero-day beginning on July 8, one day before the vendor published a fix.

These incidents highlight how quickly attackers move to exploit newly discovered weaknesses.

Administrators Should Patch Immediately

Website administrators should check whether either Joomla extension is installed.

If affected versions are in use, they should update as soon as possible to reduce the risk of compromise.

The available security updates include:

  • iCagenda 4.0.8
  • iCagenda 3.9.15
  • Balbooa Forms 2.4.1

In addition, administrators should review uploaded files, inspect server logs for suspicious activity, and look for signs of unauthorized web shells or configuration changes.

CISA Flags the Vulnerabilities as High Priority

CISA considers both vulnerabilities a high-priority threat because they are already being exploited in real-world attacks.

The agency’s inclusion of the flaws in the KEV catalog serves as a strong warning that organizations should not delay patching. Since remote code execution can lead to full website compromise, prompt updates remain the most effective defense against ongoing attacks.


0 responses to “Joomla Flaws Exploited in Active Remote Code Execution Attacks”