Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology] · au_impact: false

CVE-2026-56291

Summary

A critical vulnerability in the Balbooa Forms Joomla extension, reported as exploited as a zero-day since 15 June 2026 and added to CISA's Known Exploited Vulnerabilities catalog on 14 July 2026.

Details

The digest paired it with CVE-2026-48939 (iCagenda) as two CVSS 10.0 Joomla extension flaws exploited as zero-days from mid-June before the 14 July catalogue entry — a four-week window in which the defences available were detection and virtual patching rather than a vendor fix. Forms extensions are attractive targets in their own right because they are the parts of a site that accept input from strangers, so the exploit surface exists by design. The remediation that matters after patching is checking for content the form handler should never have written.

Attribute Detail
CVE CVE-2026-56291
CVSS 9.8
Vendor / product Balbooa Forms (Joomla extension)
Reported in the digest 2026-07-14

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-14.md