Code Defence Cyber security

CISA adds maximum severity Joomla extension vulnerabilities to KEV catalog following zero day attacks

Two maximum-severity vulnerabilities impacting prominent third-party extensions for a major content management platform have been added to the Known Exploited Vulnerabilities catalog. The bugs allow unauthenticated remote attackers to bypass validation filters to upload and execute malicious backend code files.

The flaws affect the iCagenda extension (CVE-2026-48939) and the Balbooa Forms extension (CVE-2026-56291) deployed on Joomla-based websites. Both issues involve an unrestricted file upload vulnerability, carrying perfect CVSS scores of 10.0. Threat groups are utilizing automated scanning tools to locate exposed interfaces and execute file upload queries to plant persistent web shells. Due to evidence of active zero-day exploitation, CISA has mandated swift remediation across all affected networks.

Allowing unrestricted file uploads on public web nodes completely undermines boundary controls. Once an adversary successfully uploads a PHP-based web shell, they bypass authentication gates, read database configuration files, siphon user records, and execute background commands to launch secondary attacks against internal subnets.

– Conduct an inventory review to identify if the iCagenda or Balbooa Forms extensions are installed across your web assets.

– Apply the latest secure versions and security hotfixes released by the extension developers immediately.

– Scan public-facing directory structures for unverified or newly added files with executable extensions.

– Configure web application firewalls to actively detect and block unauthorized file uploads targeting extension endpoints.

Web application security demands rigid file verification controls to ensure that external content additions cannot be manipulated into executing untrusted system commands. #CodeDefence #Joomla #UnrestrictedUpload #Webshell #CISA #KEV #VulnerabilityManagement #AppSec
/

Scroll to Top