logo

U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog

ID: 13470a10-4431-5825-a4d8-ebdef53a2c73

STIX ID: report--13470a10-4431-5825-a4d8-ebdef53a2c73

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-07-11

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

CISA added two critical Joomla extension flaws—CVE-2026-48939 (iCagenda, CVSS 10.0) and CVE-2026-56291 (Balbooa Forms)—to its Known Exploited Vulnerabilities catalog; both permit unauthenticated/unrestricted file uploads that can lead to remote code execution, and federal agencies are ordered to urgently remediate them by July 13, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.