10 out of 10 points on CVSS - and the attacks began even before the release of the patch. We understand the dangers of two critical vulnerabilities in

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
345
Reaction score
502
Deposit
0$
Two critical vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla are already used in attacks, and attackers began to act before the release of fixes. Both errors allow you to download malicious PHP-file to the site and execute the code on the server without logging in to the account.





The U.S. Cyber Security and Infrastructure Protection Agency has added vulnerabilities CVE-2026-48939 and CVE-2026-56291 to the catalogue of known exploited problems. Each received a maximum hazard score of 10 out of 10.





CVE-2026-48939 (10.0 Critical) affects the expansion of the iCgenta calendar. The error is hidden in the form of “Suppose an event”, through which visitors can send new events. The attachment mechanism does not sufficiently check the downloaded files, so the attacker can place a PHP script in the open site folder and run it.





Specialists of the service mySites.guru found automatic attacks on sites with iCagenda on June 15, 2026. The scanner with the identifier "icagenda-batch/1.0" received a protective token, sent a malicious file through the form, and then turned to the installed command shell along a known path.








The vulnerability affects the iCagenda versions 4.0.7 and below, as well as the old branch from 3.2.1 to 3.9.14 inclusive. The developers closed the problem in the issues 4.0.8 and 3.9.15. Site owners are advised to check the directory "images/icagenda/frontend/attachments/" and delete unknown PHP files.





The second vulnerability, CVE-2026-56291 (10.0 Critical), is found in Balbooa Forms versions 2.4.0 and below. The extension accepted attachments from any visitor without logging in, protective token and file type checking. As a result, the attacker could upload a PHP script to the public directory and execute commands on the server.





MySites.guru revealed the problem on July 8, 2026 after an attack on the site of one of the customers. The correction entered the Balbooa Forms 2.4.1. Administrators are advised to check the “images/baforms/uploads” folder, a Joomla list of users and recently modified PHP files. Particular attention should be paid to unknown accounts with administrator rights.





Federal civil affairs agencies are due to install updates until July 13, 2026. Owners of other sites on Joomla also better not to postpone the installation of fixes, since both vulnerabilities are already used in real attacks.
 
Top Bottom