Briefing

CISA Adds iCagenda and Balbooa Joomla Extensions to KEV Catalog for Zero‑Day Exploitation

security
by [email protected] (The Hacker News) · CVE-2026-48939

Patch iCagenda and Balbooa Joomla extensions immediately to mitigate CVE‑2026‑48939 and related zero‑day vulnerabilities.

What to do now

Patch iCagenda and Balbooa extensions immediately to mitigate CVE‑2026‑48939 and related zero‑day vulnerabilities.

Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two maximum‑severity vulnerabilities in the iCagenda and Balbooa extensions for Joomla in its Known Exploited Vulnerabilities (KEV) catalog. Both flaws carry a CVSS score of 10.0, indicating critical risk. CVE‑2026‑48939 affects the iCagenda extension, enabling remote code execution through a flaw in the extension’s input handling. The Balbooa extension suffers a similar vulnerability, also rated 10.0, allowing attackers to execute arbitrary code on the server. Zero‑day exploitation has been reported in the wild, prompting CISA to advise users to patch immediately. The advisory stresses that the extensions are widely used in Joomla sites, making the impact potentially large.

Key changes

  • iCagenda extension CVE‑2026‑48939 rated 10.0 CVSS
  • Balbooa extension also rated 10.0 CVSS
  • Zero‑day exploitation reported in the wild
  • CISA added both to the KEV catalog
  • Both extensions allow remote code execution via input handling flaws

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting