logo

CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions

ID: 9ed7b763-796e-5dec-9c29-8d78c2e5faea

STIX ID: report--9ed7b763-796e-5dec-9c29-8d78c2e5faea

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

**CISA added two critical arbitrary file upload vulnerabilities in Joomla extensions (iCagenda and Balbooa Forms) to its Known Exploited Vulnerabilities list, warning that attackers are actively exploiting these flaws to upload webshells and achieve remote code execution on affected web servers; the report outlines exploitation steps, affected environments, detection indicators (unexpected PHP uploads, log patterns, outbound connections), and remediation actions including patching, auditing uploads, and restricting upload functionality.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.