Post
CRITICAL ⚡ MUST-KNOW

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

· rce · zero-day · cve · vulnerability

CISA added two maximum-severity flaws (CVSS 10.0) affecting the iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities catalog, following reports of in-the-wild zero-day exploitation. One tracked flaw is CVE-2026-48939. Organizations running either extension should treat this as active exploitation and prioritize patching or removal immediately, per federal agency deadlines under the KEV catalog.