Skip to content

CISA Warns of Zero-Day Exploits in Joomla Extensions iCagenda and Balbooa

The Point: Two CVSS-10.0 vulnerabilities in iCagenda and Balbooa are being actively exploited as zero-day exploits, according to CISA.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security vulnerabilities in the Joomla extensions iCagenda and Balbooa to its catalog of actively exploited vulnerabilities (Known Exploited Vulnerabilities, KEV) following reports of zero-day exploits circulating.

The CISA entries document two vulnerabilities with the maximum CVSS rating of 10.0. Both extensions are widely used Joomla components deployed on thousands of websites.

For CISOs, inclusion in the KEV catalog means active exploits are circulating in the wild and timely patches are required. The maximum CVSS rating points to critical access control or authentication flaws that could enable complete system compromise.

Affected organizations should immediately check whether their Joomla installations use iCagenda or Balbooa, and depending on the availability of security updates, either patch the vulnerabilities or disable the extensions.


Source: thehackernews.com · Published 13 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: