The actively exploited iCagenda and Balbooa Forms vulnerabilities show how dangerous CMS extension flaws can become when they allow unauthenticated file uploads.
Both vulnerabilities affect Joomla extensions and have been added to CISA’s Known Exploited Vulnerabilities catalogue after reported zero-day exploitation. The iCagenda flaw allows arbitrary file uploads through the attachment feature, while the Balbooa Forms flaw allows unauthenticated uploads that can lead to remote code execution.
The risk is severe because attackers can upload PHP web shells to public folders and execute commands on the website. Once a web shell is present, attackers may steal data, modify pages, create administrator accounts, redirect visitors, host phishing content, or use the compromised site as part of a larger attack.
Organizations using Joomla should immediately update iCagenda to fixed versions and Balbooa Forms to version 2.4.1 or later. Site owners should also inspect upload directories, especially public attachment folders, for suspicious PHP files or recently modified scripts.
Patching is necessary, but it may not be enough if exploitation already occurred. Security teams should review web logs, administrator accounts, file changes, scheduled tasks, outbound connections, and any unexpected redirects.
The key lesson is that CMS extensions are not harmless add-ons. A vulnerable form or event plugin can become full server access, because apparently letting anonymous visitors upload executable files is still a thing the internet has not evolved past.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026-48939 - A vulnerability in the
Source: iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days via The Hacker News — published 13 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.