bleeping-computer · Crawled Jul 13, 2026

CISA warns of actively exploited RCE flaws in Joomla extensions

Read original article ↗

AI Summary

CISA has issued a warning about actively exploited remote code execution (RCE) vulnerabilities in two Joomla extensions, iCagenda and Balbooa Forms. The vulnerabilities, CVE-2026-48939 and CVE-2026-56291, allow attackers to upload arbitrary files, including malicious PHP scripts, leading to full website compromise. These flaws were exploited in automated attacks before patches were released, with exploitation occurring just days prior to vendor fixes.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.