CISA Adds iCagenda and Balbooa Joomla Extensions to KEV Catalog for Zero‑Day Exploitation
Patch iCagenda and Balbooa Joomla extensions immediately to mitigate CVE‑2026‑48939 and related zero‑day vulnerabilities.
Patch iCagenda and Balbooa extensions immediately to mitigate CVE‑2026‑48939 and related zero‑day vulnerabilities.
Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two maximum‑severity vulnerabilities in the iCagenda and Balbooa extensions for Joomla in its Known Exploited Vulnerabilities (KEV) catalog. Both flaws carry a CVSS score of 10.0, indicating critical risk. CVE‑2026‑48939 affects the iCagenda extension, enabling remote code execution through a flaw in the extension’s input handling. The Balbooa extension suffers a similar vulnerability, also rated 10.0, allowing attackers to execute arbitrary code on the server. Zero‑day exploitation has been reported in the wild, prompting CISA to advise users to patch immediately. The advisory stresses that the extensions are widely used in Joomla sites, making the impact potentially large.
Key changes
- iCagenda extension CVE‑2026‑48939 rated 10.0 CVSS
- Balbooa extension also rated 10.0 CVSS
- Zero‑day exploitation reported in the wild
- CISA added both to the KEV catalog
- Both extensions allow remote code execution via input handling flaws