CRITICAL ⚡ MUST-KNOW
iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days, Added to CISA KEV
CISA has added two maximum-severity flaws in the iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation in the wild. Both vulnerabilities, including CVE-2026-48939, are rated 10.0 on the CVSS scale and enable remote code execution through arbitrary file uploads. Organizations running the affected Joomla extensions should patch immediately or disable them until a fix is applied, given confirmed active exploitation.