logo

Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites

ID: d0667866-7e8b-5c5f-b48a-dd6656f8afaa

STIX ID: report--d0667866-7e8b-5c5f-b48a-dd6656f8afaa

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-07-14

Date Updated: 2026-07-23

...
...

CISA added two critical Joomla extension vulnerabilities (iCagenda CVE-2026-48939 and Balbooa Forms CVE-2026-56291) to its Known Exploited Vulnerabilities catalog after in-the-wild exploitation enabled unauthenticated file uploads and remote code execution; researchers observed automated scanning and web-shell deployment, and vendors released patched versions though attacks continue against unpatched sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.