A serious cybersecurity issue has been discovered in two popular Joomla extensions, iCagenda and Balbooa Forms. Security researchers confirmed that both vulnerabilities were being actively exploited by attackers before official fixes were released, making them true zero-day vulnerabilities. Because these extensions are widely used on Joomla websites, thousands of websites could have been exposed to remote attacks.

The first vulnerability affects the iCagenda extension and has been identified as CVE-2026-48939. Researchers found that the event submission feature failed to properly validate uploaded files. As a result, an unauthenticated attacker could upload a malicious PHP file and execute it on the server, leading to full remote code execution. The issue mainly impacts Joomla 6 installations, while another access control bypass affects multiple Joomla versions.
Investigators reported that attackers did not need to create an account or log in to exploit the flaw. They only needed to obtain a valid security token from a public iCagenda page before sending a specially crafted request. Security experts observed automated scanning tools performing these attacks in real-world environments before a security update became available, confirming active exploitation in the wild.

The iCagenda developers responded quickly after responsible disclosure and released patched versions 4.0.8 for the current branch and 3.9.15 for the legacy branch. Website administrators are strongly advised to upgrade immediately because any earlier version should be considered vulnerable. Experts also recommend checking websites for unauthorized files or suspicious activity, especially if updates were delayed.
The second zero-day vulnerability affects the Balbooa Forms Joomla extension and is tracked as CVE-2026-56291. This flaw also involves an unauthenticated file upload vulnerability that allows attackers to upload executable PHP files directly to the server. Once uploaded, the malicious file can be executed remotely, giving attackers complete control over the affected website. The vulnerability received a maximum CVSS score of 10.0, highlighting its critical severity.

Security researchers stated that the Balbooa Forms vulnerability existed in all versions up to 2.4.0. The extension accepted uploaded files without proper authentication, CSRF protection, or strict validation of file extensions. Attackers were already abusing this weakness before a patch became available, making it another confirmed zero-day exploited in real-world attacks.
To address the issue, the Balbooa development team released version 2.4.1, which adds proper server-side validation and fixes the dangerous upload mechanism. Security professionals recommend updating all affected Joomla websites immediately and conducting a full security review after patching. Administrators should also look for unknown files, unexpected administrator accounts, or other signs that a website may have already been compromised.

Due to confirmed evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both the iCagenda and Balbooa Forms vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Their inclusion means organizations should treat these flaws as high-priority security risks and apply the available updates without delay. Keeping Joomla extensions updated and regularly monitoring websites remain essential steps to reduce the risk of compromise.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news