CVE-2026-56291
Summary
A critical vulnerability in the Balbooa Forms Joomla extension, reported as exploited as a zero-day since 15 June 2026 and added to CISA's Known Exploited Vulnerabilities catalog on 14 July 2026.
Details
The digest paired it with CVE-2026-48939 (iCagenda) as two CVSS 10.0 Joomla extension flaws exploited as zero-days from mid-June before the 14 July catalogue entry — a four-week window in which the defences available were detection and virtual patching rather than a vendor fix. Forms extensions are attractive targets in their own right because they are the parts of a site that accept input from strangers, so the exploit surface exists by design. The remediation that matters after patching is checking for content the form handler should never have written.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-56291 |
| CVSS | 9.8 |
| Vendor / product | Balbooa Forms (Joomla extension) |
| Reported in the digest | 2026-07-14 |
Related Pages
- Cve 2026 48939 (companion Joomla zero-day, same exploitation window)
- Source article
Sources: raw/digests/Cyber-Digest-2026-07-14.md