CuraSec

Act archived

CISA: Joomla iCagenda and Balbooa Forms extensions actively exploited for RCE

2026-07-14 12:08 UTC · BleepingComputer · read the source ↗ #joomla#rce#active-exploitation
  • Engineer — Act: CISA warning signals KEV-level active exploitation — update or disable the iCagenda and Balbooa Forms Joomla extensions immediately, and audit web roots for unexpectedly uploaded files that may indicate prior compromise.
  • SOC/IR — Act: Active exploitation via arbitrary file upload means webshells may already be in place — hunt Joomla web directories for recently uploaded executables and review web server logs for POST requests targeting these extension upload endpoints.
  • Leader — Plan: Confirm whether any company-owned or vendor-hosted web properties run Joomla with these extensions and verify engineering teams have patch SLAs in motion; this does not yet rise to board-briefing level.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.