Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology] · au_impact: false

CVE-2026-48939

Summary

A critical vulnerability in the iCagenda Joomla extension, reported as exploited as a zero-day since 15 June 2026 and added to CISA's Known Exploited Vulnerabilities catalog on 14 July 2026.

Details

The month between the first exploitation and the KEV listing is the story here: for four weeks this was an unpatched zero-day in a widely installed events-calendar extension, and the digest recorded the exploitation as having begun on 15 June, well before the catalogue entry. Extensions of this class are installed for a single function and rarely reviewed afterwards, so the exposure persists long after the site owner has stopped thinking about them. Its companion in the same batch, Balbooa Forms (CVE-2026-56291), followed the identical pattern.

Attribute Detail
CVE CVE-2026-48939
CVSS 9.8
Vendor / product iCagenda (Joomla extension)
Reported in the digest 2026-07-14

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-14.md