- Engineer — Act: CISA KEV-listed, CVSS 10.0, actively exploited as zero-days with a public PoC on GitHub — patch iCagenda and Balbooa Forms Joomla extensions to the latest fixed versions immediately if these are in your stack.
- SOC/IR — Act: In-the-wild zero-day exploitation of web-facing Joomla components means you should assume compromise may predate patching — sweep web access logs for anomalous requests targeting these extension endpoints and confirm whether any estate assets run Joomla with either plugin.
- Leader — Plan: CISA KEV listing at CVSS 10.0 warrants a same-week inventory check of web properties for Joomla usage with these extensions; if confirmed in use, escalate to engineering for urgent remediation before this surfaces in a customer questionnaire or audit.
- Signals: CVE-2026-48939 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub