U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog
ID: 13470a10-4431-5825-a4d8-ebdef53a2c73
STIX ID: report--13470a10-4431-5825-a4d8-ebdef53a2c73
Feed Name: Security Affairs
Threat Score
CISA added two critical Joomla extension flaws—CVE-2026-48939 (iCagenda, CVSS 10.0) and CVE-2026-56291 (Balbooa Forms)—to its Known Exploited Vulnerabilities catalog; both permit unauthenticated/unrestricted file uploads that can lead to remote code execution, and federal agencies are ordered to urgently remediate them by July 13, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
