Two zero-day vulnerabilities in Joomla: what to check right now

Colleagues, I’d like to draw attention to a cybersecurity issue: two critical vulnerabilities in Joomla extensions iCagenda and Balbooa Forms are already being actively exploited.
- iCagenda allowed arbitrary file upload and PHP code execution.
- Balbooa Forms permitted file uploads without validation, leading to remote code execution.
- Both cases have been added to CISA’s KEV catalog, and ACSC warns of a global campaign targeting CMSs and plugins.
I strongly recommend urgently checking versions, applying patches 4.0.8 / 3.9.15 for iCagenda and 2.4.1 for Balbooa Forms, and reviewing upload folders and the admin list.
Why this matters: such vulnerabilities often end with web shell installation and full site compromise.
Have you already checked your Joomla installations?
#cybersecurity #Joomla #ZeroDay #Vulnerability

