logo

CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities

ID: f907af09-a7e7-5746-a9d2-63e3fc6a649a

STIX ID: report--f907af09-a7e7-5746-a9d2-63e3fc6a649a

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: Ashish Khaitan

...
...

CISA added two critical Joomla extension vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa) to its Known Exploited Vulnerabilities catalog after confirmed active zero‑day attacks that allow unauthenticated file uploads and remote code execution; administrators are urged to apply patches and inspect upload directories for web shells. The report also highlights a broader global CMS plugin exploitation campaign targeting multiple platforms and provides detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.