Act
archived
CISA: Joomla iCagenda and Balbooa Forms extensions actively exploited for RCE
- Engineer — Act: CISA warning signals KEV-level active exploitation — update or disable the iCagenda and Balbooa Forms Joomla extensions immediately, and audit web roots for unexpectedly uploaded files that may indicate prior compromise.
- SOC/IR — Act: Active exploitation via arbitrary file upload means webshells may already be in place — hunt Joomla web directories for recently uploaded executables and review web server logs for POST requests targeting these extension upload endpoints.
- Leader — Plan: Confirm whether any company-owned or vendor-hosted web properties run Joomla with these extensions and verify engineering teams have patch SLAs in motion; this does not yet rise to board-briefing level.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.