News Room
16
Share
CISA Adds Critical Joomla Extension Zero-Days to KEV Catalog Amid Widespread Automated RCE Attacks
criticalZero-Day Exploits

CISA Adds Critical Joomla Extension Zero-Days to KEV Catalog Amid Widespread Automated RCE Attacks

CISA has added two maximum-severity vulnerabilities (CVE-2026-48939 and CVE-2026-56291) to its KEV catalog following reports of automated zero-day exploitation targeting Joomla-based web servers.

13 July 2026Last updated 20 August 20265 min readCISA / The Hacker News
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-48939, CVE-2026-56291
Source:
CISA / The Hacker News
Read Time:
5 min

Executive Summary\nOn July 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two maximum-severity vulnerabilities impacting Joomla extensions to its Known Exploited Vulnerabilities (KEV) catalog. The flaws, identified as CVE-2026-48939 and CVE-2026-56291, affect the iCagenda and Balbooa Forms extensions, respectively. Both vulnerabilities carry a CVSS score of 10.0 and are currently being leveraged by threat actors to achieve unauthenticated remote code execution (RCE) on target web servers. Reports from intelligence partners indicate that these flaws have been exploited as zero-days since mid-June 2026, primarily through automated scanning and exploitation campaigns targeting vulnerable web infrastructure globally.\n\n## Threat Analysis\nThe threat involves highly automated botnets scanning for publicly accessible Joomla installations with these specific extensions enabled. Security researchers at mySites.guru identified an automated scanner using the custom User-Agent 'icagenda-batch/1.0' which systematically probes for the 'Submit an Event' endpoint in iCagenda. Once a vulnerable target is identified, the scanner bypasses security checks to upload a malicious PHP web shell disguised as a benign attachment. This allows the attacker to execute arbitrary commands, browse the local file system, and establish a permanent foothold within the environment. The exploitation of Balbooa Forms follows a similar pattern, where a flaw in the frontend attachment upload feature allows any anonymous visitor to upload executable scripts without requiring a login or valid CSRF token.\n\n## Technical Details\nCVE-2026-48939 is an arbitrary file upload vulnerability in iCagenda versions 3.2.1 through 3.9.14 (Legacy) and 4.0.x up to 4.0.7. The flaw resides in the event submission form’s file attachment functionality, which fails to properly sanitize or restrict the types of files uploaded to the server. An attacker can upload a .php file and invoke it directly from the 'images/icagenda/frontend/attachments/' directory. CVE-2026-56291 impacts Balbooa Forms up to and including version 2.4.0, where the 'frontend attachment upload' component lacks proper authorization and file type verification. Both vulnerabilities effectively allow an attacker to bypass the entire security stack of the web application and run code with the permissions of the web server user (e.g., www-data), leading to full system compromise.\n\n## Attribution Assessment\nAttribution for these attacks remains broad, as current exploitation activity is characterized as highly automated and opportunistic. The techniques, including the use of simple PHP shells and widespread scanning patterns, are typical of cybercriminal groups specializing in initial access brokerage or the assembly of large-scale botnets for SEO spam, crypto-mining, or ransomware delivery. While no specific nation-state actor has been linked to these events yet, the mass exploitation of content management system (CMS) plugins is a frequent precursor to more targeted second-stage attacks against government and commercial organizations by advanced persistent threat (APT) actors seeking persistence on public-facing assets.\n\n## Implications\nThe immediate implication of these zero-days is the total compromise of affected Joomla sites. Successful exploitation permits attackers to exfiltrate sensitive database information, including administrative credentials, configuration secrets, and customer data. Furthermore, compromised web servers can be used as pivot points to reach internal network segments or to host malicious payloads for watering hole attacks targeting visitors. For Federal Civilian Executive Branch (FCEB) agencies, the addition of these CVEs to the KEV catalog mandates immediate remediation, highlighting the high volume of compromised instances detected across the internet since the exploitation began in June.\n\n## Recommendations\nEncrygma recommends that organizations utilizing Joomla immediately audit their installed extensions for iCagenda and Balbooa Forms. It is critical to update iCagenda to version 4.0.8 or 3.9.15 and Balbooa Forms to version 2.4.1. Beyond patching, administrators should scan the 'images/icagenda/frontend/attachments/' and equivalent forms directories for unexpected PHP files or suspicious scripts. Implementing a Web Application Firewall (WAF) with rules to block the 'icagenda-batch/1.0' user-agent and unauthorized file uploads to known plugin paths is highly recommended. Finally, organizations should ensure that file permissions in upload directories are set to prevent the execution of scripts and monitor for any unauthorized changes to system-level configuration files.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo