CISA added Balbooa Forms and iCagenda to its catalog of vulnerabilities being exploited right now. Both allow unauthenticated file upload and code execution on the server. Three days earlier, two other Joomla extensions joined the same list - with the same hole.
- CVE-2026-56291 (Balbooa Forms) and CVE-2026-48939 (iCagenda) joined CISA's KEV catalog on 10 July 2026.
- Both: unauthenticated file upload leading to code execution. CVSS 9.8 (v3.1) / 10.0 (v4.0).
- On 7 July, the same catalog gained SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), with the same profile.
CISA confirmed active exploitation of two vulnerabilities in Joomla (a website content management system) extensions. Balbooa Forms and iCagenda joined the KEV catalog on 10 July - both with the same mechanism: file upload with no password, leading to code execution on the server. It's not an isolated case. Three days earlier, SP Page Builder and Page Builder CK joined the same catalog, with practically the same flaw. Four different authors. The same mistake, in four days.
No filler - being on this catalog means one thing: CISA has seen real attacks, not theory. In practice it looks like this - you upload a file into a field for an attachment or a logo, and it runs as code on the server, no password needed. The hole isn't in Joomla, it's in the extensions. Four different authors made the same mistake - accepting an uploaded file without checking what it actually is. The core is maintained by a team with a process. An extension is maintained by one person in their spare time. Attackers aren't looking for Joomla. They're looking for the extension.
The action is simple. Got Balbooa Forms? Update to 2.4.1. Got iCagenda? Update to 3.9.15 or 4.0.8. Check both builder-based extensions - the page builders - if you've got them installed. And make the effort to list what extensions you're actually running - this applies to any plugin-based system, including WordPress. Nobody keeps a list of the third-party code they let onto their own site. That's exactly where the door is.