CISA added two maximum-severity (CVSS 10.0) zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 13, 2026: CVE-2026-48939 in the iCagenda extension for Joomla, and CVE-2026-56291 in the Balbooa Forms extension. Both flaws allow unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution — the worst outcome possible for a web vulnerability.

CVE-2026-48939 has been actively exploited in automated attacks since June 15, 2026, via iCagenda’s “Submit an Event” feature. Attackers are scanning for exposed endpoints, uploading PHP shells to images/icagenda/frontend/attachments/, and executing them immediately. The flaw affects iCagenda 4.x through 4.0.7 and legacy 3.x releases; patches are available in versions 4.0.8 and 3.9.15. CVE-2026-56291 in Balbooa Forms (versions up to 2.4.0) was caught in an active attack on July 8, 2026; version 2.4.1 patches it. The Australian Cyber Security Centre separately warned of a broader global campaign targeting vulnerable CMS platforms including these two extensions alongside Sneeit Framework, WPBookit, and Gravity Forms.

Federal Civilian Executive Branch agencies have until July 13, 2026 to apply available patches under CISA’s Binding Operational Directive. Administrators should immediately inspect upload directories for unexpected PHP files and audit Joomla admin accounts for unauthorized additions.

Sources

Commentary

Two CVSS 10.0 Joomla extension flaws in active mass exploitation is a reminder that the CMS ecosystem remains a soft underbelly of the web. Extension code often doesn’t receive the same security scrutiny as the core platform, yet it runs in the same server context with full file-write access. The June 15 start date for CVE-2026-48939 exploitation means attackers had nearly four weeks of head start before KEV listing — if you run Joomla with either extension installed, assume compromise and work backwards. Check upload directories, audit admin accounts, and review recently modified PHP files across the entire site tree.

By Allan