CVE-2026-48939 has been exploited as a zero-day since June 15, 2026, according to mySites.guru, marking the opening act in a broader wave of automated attacks against popular content-management-system extensions.
CVE-2026-48939: iCagenda's upload flaw and observed exploitation
The iCagenda extension for Joomla contains a maximum-severity vulnerability, CVE-2026-48939, scored 10.0 on the CVSS scale, that permits arbitrary-file upload via the component's file attachment feature. mySites.guru reports the bug resides in the "Submit an Event" form, which accepts proposals for calendar events.
mySites.guru described the attack pattern in detail: "an automated scanner identifying itself as 'icagenda-batch/1.0' grabbed a token, posted a malicious upload to the submit endpoint, then fetched the planted shell at the exact path the component writes attachments to." The component writes attachments to the images/icagenda/frontend/attachments/ folder; site owners are advised to check that folder for suspicious PHP files and remove any found.
The flaw affects iCagenda 4.x versions up to and including 4.0.7 and legacy 3.x versions from 3.2.1 through 3.9.14. JoomliC has released fixes in versions 4.0.8 and 3.9.15.
CVE-2026-56291: Balbooa Forms unauthenticated upload and discovery
Balbooa Forms for Joomla is the other maximum-severity entry added to the Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-56291, also scored 10.0. The flaw allows arbitrary file uploads from anonymous visitors, leading to unauthenticated remote code execution when a PHP payload is accepted and later executed.
mySites.guru reported discovery of CVE-2026-56291 on July 8, 2026, after a live attack against one of its customers. The vulnerability affected Balbooa Forms versions up to and including 2.4.0 and was patched in 2.4.1.
The service provided concrete indicators of compromise: inspect the Balbooa upload folder (by default images/baforms/uploads) for files that are not images or documents, particularly anything ending in .php; check the Joomla user list for suspicious administrator accounts; and audit the site for recently modified or unfamiliar PHP files.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageCISA response and FCEB deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation. Because both flaws enable remote code execution and have been exploited in the wild, Federal Civilian Executive Branch (FCEB) agencies were given a compliance deadline of July 13, 2026, to implement the fixes on their networks.
Both vulnerabilities carry a worst-case outcome—unauthenticated remote code execution—prompting the KEV listing and the associated federal timeline for mitigation.
Australian Cyber Security Centre: a global campaign targeting CMS systems
The disclosure of these Joomla flaws coincides with an alert from the Australian Cyber Security Centre (ACSC) warning of "a global exploitation campaign targeting various vulnerabilities in content management systems (CMS) and plugins." The ACSC said, "As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy web shells, leveraging various vulnerabilities affecting CMS software and plugins."
The ACSC listed a sampling of vulnerabilities observed in the campaign, including CVE-2025-6389 (Sneeit Framework), CVE-2025-7852 (WPBookit), CVE-2025-12352 (Gravity Forms), CVE-2025-32432 (Craft CMS), CVE-2026-0740 (Ninja Forms), CVE-2026-3395 (MaxSite CMS), CVE-2026-3844 (Breeze Cache), CVE-2025-12057 (WavePlayer), CVE-2026-29014 (MetInfo CMS), and CVE-2026-48907 (Joomla JCE).
The ACSC emphasized the operational effect of these intrusions: once web shells are deployed they "serve as conduits for remote access and control of the targeted web servers." The agency added: "This highly scaled global exploitation campaign demonstrates the rapidly evolving cyber risk facing organisations," and warned that "advances in AI are accelerating the speed and scale of cyber operations, reducing the time between vulnerability disclosure and exploitation."
What this means for site owners, FCEB agencies, and security teams
- Site owners and administrators: Prioritize immediate patching—update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1. Audit the indicated upload folders (images/icagenda/frontend/attachments/ and images/baforms/uploads) for non-image/document files, especially .php files, and remove any planted shells.
- FCEB agencies and compliance teams: Apply the fixes required under the CISA KEV deadline (July 13, 2026) and audit Joomla instances for suspicious administrator accounts and unfamiliar PHP files, as advised by mySites.guru.
- Security operations and incident response teams: Treat presence of web shells as immediate root-cause evidence of remote access; follow indicators of compromise supplied by mySites.guru and conduct a site-wide search for modified or unfamiliar PHP artifacts and unauthorized administrator accounts.
The combined advisories from mySites.guru, CISA, and the ACSC make clear that these are not isolated bugs but components of a higher-scale campaign of automated scanning and exploitation. For administrators running affected Joomla extensions, the immediate steps are unambiguous: patch, search the cited upload directories, and investigate any unexpected administrator accounts or PHP files. Whether defenders can keep pace as automated scanners and AI-accelerated tooling proliferate will be the near-term test; for now the fixes are published and the indicators are specific.




