Two more Joomla extensions hit CISA KEV: iCagenda and Balbooa Forms
CISA added CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) to KEV on July 10. Both unauth file-upload to RCE. Patches: iCagenda 4.0.8/3.9.15, Balbooa Forms 2.4.1.
CISA added CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) to KEV on July 10. Both unauth file-upload to RCE. Patches: iCagenda 4.0.8/3.9.15, Balbooa Forms 2.4.1.
CISA added CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Page Builder CK) to KEV on July 7. Both CVSS 10.0, unauth file-upload to RCE. FCEB deadline: July 10.
CISA added CVE-2026-48907 to KEV on June 16 — an unauth profile-import chain in the JCE Joomla extension that lets attackers upload and execute PHP. Patch in JCE 2.9.99.5.