news.mlab.sh
2 results
vulnerability

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file uploads, and CISA has added them to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian…

The Hacker News · Jul 13, 2026 Critical