CRITICALVulnerability
Global

CISA warns of actively exploited RCE flaws in Joomla extensions

·Source: BleepingComputer

Updated:

Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]

Analysis

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]
Source Attribution

Originally published by BleepingComputer on Jul 13, 2026.

Related Threats