<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Joomla on CuraSec</title><link>https://curasec.metacog.co.kr/tags/joomla/</link><description>Recent content in Joomla on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 14 Jul 2026 12:08:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/joomla/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA: Joomla iCagenda and Balbooa Forms extensions actively exploited for RCE</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-cisa-warns-of-actively-exploited-rce-flaws-in-joomla-extensi/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-cisa-warns-of-actively-exploited-rce-flaws-in-joomla-extensi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA warning signals KEV-level active exploitation — update or disable the iCagenda and Balbooa Forms Joomla extensions immediately, and audit web roots for unexpectedly uploaded files that may indicate prior compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation via arbitrary file upload means webshells may already be in place — hunt Joomla web directories for recently uploaded executables and review web server logs for POST requests targeting these extension upload endpoints.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether any company-owned or vendor-hosted web properties run Joomla with these extensions and verify engineering teams have patch SLAs in motion; this does not yet rise to board-briefing level.&lt;/li>
&lt;/ul></description></item><item><title>Joomla iCagenda &amp; Balbooa Forms Zero-Days Added to CISA KEV</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploited/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploited/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA KEV-listed, CVSS 10.0, actively exploited as zero-days with a public PoC on GitHub — patch iCagenda and Balbooa Forms Joomla extensions to the latest fixed versions immediately if these are in your stack.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> In-the-wild zero-day exploitation of web-facing Joomla components means you should assume compromise may predate patching — sweep web access logs for anomalous requests targeting these extension endpoints and confirm whether any estate assets run Joomla with either plugin.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> CISA KEV listing at CVSS 10.0 warrants a same-week inventory check of web properties for Joomla usage with these extensions; if confirmed in use, escalate to engineering for urgent remediation before this surfaces in a customer questionnaire or audit.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-48939 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>