The images in this article were generated with artificial intelligence. How we publish
The incorporation by the U.S. agency CISA of two maximum-gravity security failures into the Known Exploited Vulnerables (KEV) catalogue redemonstrates the pressure that CMS platforms suffer: we are facing unauthenticated file uploading vulnerabilities that allow remote code execution, a scenario that attackers exploit to deploy web shells and obtain persistent control over web servers.
The failures affect much-used extensions: iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291), both rated with 10.0 on the CVSS scale. In practical terms, this means that an anonymous visitor could upload an executable PHP file and trigger a remote execution on the server. MySites.guru researchers documented active automated attacks: in the case of iCagenda, a scanner that was identified as 'icagenda-batch / 1.0 ' He stole a token, raised a payload and then accessed the shell planted on the public route where the component keeps the attachments.

The affected versions already have patches: iCagenda was corrected in 4.0.8 and 3.9.15, while Balbooa Forms published the correction in 2.4.1. Given the evidence of exploitation in nature and the potential impact - remote access, side movements and possible escalation to exfiltration or ansomware campaigns - CISA gave strict deadlines to federal agencies and response teams recommend acting immediately.
If you manage Joomla sites, the urgent measures are practical and must be implemented in this order: apply the official updates of the above-mentioned extensions, inspect the public folders where they are usually kept attached (e.g. images / icagenda / front / attachments / and images / baforms / uploads) in search of PHP files or atypical names, review access records for scanning patterns (including the quoted user agent) and audit the Joomla user list for unauthorized administrative accounts. If you detect suspicious files, remove a copy for forensic analysis and remove the malicious load; if there are signs of commitment, isolate the server and run a restoration from a reliable copy after cleaning the intrusion.
Beyond the immediate reaction, it is appropriate to strengthen controls that mitigate this type of vector: impose strict validation of the file type on the server, configure Web Application Firewalls (WAF) to block invalid loads, apply minimum privilege principles in the file system and rotate credentials. Visibility is also key: to implement alerts on PHP file creation / modification on public routes, to preserve logs and to correlate them with IoC lists published by discovers.

The scope of the campaign is global and not limited to Joomla; the Australian ACSC agency issued a warning pointing to a wave of mass scans looking for vulnerabilities in multiple CMS and plugins, taking advantage of fragments that allow uploading files, CERs or SSRF. In its statement the ACSC warns that the advances in automation and IA are accelerating the window between the disclosure of vulnerabilities and their exploitation, which forces to accelerate the processes of patching and detection. See the ACSC page for details and recommendations: https: / / www.cyber.gov.au / acsc.
Organizations with responsibility for web infrastructure should use the CISA KEV catalogue as a reference to prioritize mitigation and check whether their inventory matches known operating inputs: https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog. It is also advisable to monitor the Joomla security centre for extensions related notices and patches: https: / / develop.joomla.org / security-centre.html.
In short, these vulnerabilities illustrate two simultaneous realities: third-party extensions remain a dominant vector for compromising websites, and the ability of attackers to automate discovery and exploitation forces teams to improve speed and discipline in patch management, detection and response. Acting now - patching, inspecting, and tightening controls - is the most effective way to prevent a timely intrusion from becoming a major gap.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...