CISA KEV Catalog Addition: iCagenda and Balbooa Forms Unrestricted File Upload Vulnerabilities
First seen Jul 11, 2026 · Updated Jul 11, 2026
CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: an unrestricted file upload flaw in iCagenda (CVE-2026-48939) and a similar flaw in Balbooa Forms (CVE-2026-56291). Both vulnerabilities allow attackers to upload dangerous file types, potentially leading to remote code execution on affected web servers.
Technical Analysis
CVE-2026-48939 and CVE-2026-56291 are classified as Unrestricted Upload of File with Dangerous Type vulnerabilities (CWE-434), commonly found in CMS plugins/extensions such as iCagenda (Joomla event management) and Balbooa Forms. These flaws typically allow an unauthenticated or low-privileged attacker to upload web shells or executable payloads by bypassing file-type validation, resulting in remote code execution on the underlying web server. Given active exploitation confirmed by CISA, threat actors are likely leveraging automated scanning to identify vulnerable installations and deploy backdoors for persistent access. If these compromised web servers host or interface with RAG pipelines, internal APIs, or agent orchestration tools that fetch data from these CMS platforms, attacker-planted web shells could be used to exfiltrate API keys, poison retrieved content, or pivot into agent-connected infrastructure, making this agent-relevant for organizations that integrate CMS-hosted content into LLM/agent workflows.
Affected Systems
iCagenda (Joomla extension) - versions vulnerable to CVE-2026-48939; Balbooa Forms (web form builder/plugin) - versions vulnerable to CVE-2026-56291; any web servers/CMS installations running these unpatched components
Indicators of Compromise
- No specific hashes, IPs, or domains provided in source data; refer to CISA KEV Catalog and CVE.org records for CVE-2026-48939 and CVE-2026-56291 for updates
Remediation Steps
- 1
Patch affected components
Update iCagenda and Balbooa Forms plugins to the latest patched versions as soon as vendor fixes are available.
- 2
Review KEV Catalog compliance
FCEB agencies must remediate per BOD 26-04 timelines; all organizations should prioritize based on exposure and exploitation risk.
- 3
Check for prior compromise
Audit web server logs and file directories for unauthorized uploaded files, web shells, or unusual file extensions predating the patch.
- 4
Restrict file upload functionality
Implement strict file-type validation, content-type checks, and sandboxing for any upload features on public-facing web applications.
- 5
Monitor for lateral movement
If compromised web hosts interact with internal APIs, credential stores, or agent/RAG systems, rotate exposed API keys and audit downstream data access.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.