CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities
ID: f907af09-a7e7-5746-a9d2-63e3fc6a649a
STIX ID: report--f907af09-a7e7-5746-a9d2-63e3fc6a649a
Feed Name: The Cyber Express
CISA added two critical Joomla extension vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa) to its Known Exploited Vulnerabilities catalog after confirmed active zero‑day attacks that allow unauthenticated file uploads and remote code execution; administrators are urged to apply patches and inspect upload directories for web shells. The report also highlights a broader global CMS plugin exploitation campaign targeting multiple platforms and provides detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
