CRITICAL ⚡ MUST-KNOW
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA added two maximum-severity flaws (CVSS 10.0) affecting the iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities catalog, following reports of in-the-wild zero-day exploitation. One tracked flaw is CVE-2026-48939. Organizations running either extension should treat this as active exploitation and prioritize patching or removal immediately, per federal agency deadlines under the KEV catalog.