iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

July 13, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Joomla website administrators
Incident: Active zero-day exploitation of critical file upload vulnerabilities in Joomla extensions.
Impact: Full system compromise via unauthenticated remote code execution.
Attacker: Unidentified threat actors
Analysis: Two maximum-severity vulnerabilities allow unauthenticated attackers to upload malicious PHP files, resulting in full remote code execution. These flaws were exploited as zero-days, meaning attacks occurred before patches were available. The activity appears to be part of a larger, AI-accelerated global campaign targeting content management systems.
Recommendations: Update iCagenda to version 4.0.8/3.9.15 and Balbooa Forms to 2.4.1 immediately.; Scan the attachments and uploads folders for unauthorized PHP files or web shells.; Audit Joomla administrator accounts for any recently created or suspicious users.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *