CVE-2026-56291Active Exploitation(balbooa / forms)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch balbooa forms systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-13. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forms

Threat summary

  • Active exploitation appears in 31 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 54 mentions across 16 observed days

What's happening

  • Active exploitation reported across 31 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 44 signals
  • Disclosure: 8 classified signals
  • Peaked 11d ago at 14 mentions (2026-07-13); latest day: 7
  • 54 total mentions across 16 days

Affected systems

Vendors
Products
forms

Deep dive

Activity timeline54 mentions / 16d
0471114Mentions · 2026-07-09: 1Mentions · 2026-07-10: 3Mentions · 2026-07-11: 7Mentions · 2026-07-12: 4Mentions · 2026-07-13: 14Mentions · 2026-07-14: 4Mentions · 2026-07-15: 2Mentions · 2026-07-16: 4Mentions · 2026-07-18: 1Mentions · 2026-07-20: 1Mentions · 2026-07-21: 1Mentions · 2026-07-27: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Mentions · 2026-08-19: 2Mentions · 2026-09-12: 7PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-18: 1PoC Mentioned / Linked · 2026-09-12: 7Exploit Tool / Code · 2026-07-13: 1Exploit Tool / Code · 2026-07-14: 1Exploit Tool / Code · 2026-09-12: 1Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-11: 4Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-13: 10Active Exploitation · 2026-07-14: 3Active Exploitation · 2026-07-15: 2Active Exploitation · 2026-07-16: 4Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-07-27: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-07-12: 2Patch / Workaround · 2026-07-13: 10Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-11: 6Technical Details · 2026-07-12: 4Technical Details · 2026-07-13: 14Technical Details · 2026-07-14: 4Technical Details · 2026-07-15: 2Technical Details · 2026-07-16: 3Technical Details · 2026-07-18: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-21: 1Technical Details · 2026-07-27: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-19: 2Technical Details · 2026-09-12: 107-0907-1007-1107-1207-1307-1407-1507-1607-1807-2007-2107-2708-0508-0608-1909-12
Signal classification5 categories
Active Exploitation
3055.6%
Disclosure
814.8%
PoC
713.0%
Patch
611.1%
General
35.6%
Referenced assets43 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-091
Active Exploitation1
2026-07-103
Disclosure2General1
2026-07-117
Active Exploitation4Disclosure2General1
2026-07-124
Active Exploitation1Disclosure2Patch1
2026-07-1314
Active Exploitation9Patch5
2026-07-144
Active Exploitation3PoC1
2026-07-152
Active Exploitation2
2026-07-164
Active Exploitation4
2026-07-181
Disclosure1
2026-07-201
Active Exploitation1
2026-07-211
Active Exploitation1
2026-07-271
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-061
General1
2026-08-192
Active Exploitation1Disclosure1
2026-09-127
Active Exploitation1PoC6
Full discourse20 posts
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The briefing reports several CVEs, including two Microsoft zero‑days and an old Cisco IOS flaw, all of which are confirmed to be actively exploited; immediate patching and mitigation steps are strongly recommended.

    33032123.8K
    125.1K followersView on X
  • CISA Cyber@CISACyber
    General

    🛡️ We added iCagenda vulnerability CVE-2026-48939 &amp; Balbooa Forms vulnerability CVE-2026-56291 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q &amp; apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/R2FueU753j

    Post summary

    The tweet announces that CVE-2026-48939 and CVE-2026-56291 have been added to the DHS KEV catalog and urges applying general mitigations, but it lacks specific technical or exploit details.

    3801728.2K
    302.1K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-56291 PT ID: PT-2026-56777 Vendor: Joomla Product: Balbooa Forms extension for Joomla (http://balbooa.com) Description: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-56777 • https://github.com/0xdenis77/CVE-2026-56291 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE-2026-56291 has been published, illustrating an unauthenticated file upload that enables remote code execution on Joomla’s Balbooa Forms extension.

    0301585.6K
    3.4K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 Two Critical Joomla Flaws Exploited as Zero-Days CISA has added two maximum-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: ⚠️ CVE-2026-48939: iCagenda arbitrary file upload ⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote code execution Both flaws carry a CVSS score of 10.0 Attackers can upload malicious PHP files and deploy web shells Affected users should immediately update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1, then inspect their Joomla environments for suspicious PHP files and unauthorized administrator accounts. Analyst Note: Installing the patch does not remove an existing compromise. Organizations must perform a full integrity review, rotate credentials, and investigate historical access logs. #DDW #Intelligence #DarkWeb #Joomla

    Post summary

    CISA reports two high‑severity Joomla vulnerabilities (CVE‑2026‑48939 and CVE‑2026‑56291) are being actively exploited as zero‑days; users should immediately patch and perform integrity checks.

    0301747.4K
    202.1K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/10追加) 🛡CVE-2026-48939 ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 iCagenda extension に存在する、危険なタイプのファイルをアップロードできる脆弱性です。 ファイル添付機能を通じて任意ファイルをアップロードでき、最終的に PHP コードのアップロードおよび実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月13日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで iCagenda extension を使用している ・iCagenda 3.2.1 から 3.9.14、または 4.0.0 から 4.0.7 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・Joomla 6 環境では PHP Web シェルのアップロードおよび実行につながる可能性がある ・iCagenda 3.9.15 または 4.0.8 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者にファイル添付機能を悪用される可能性がある ・PHP ファイルを Web ルート配下の添付ファイル保存先へ配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェル、バックドア設置、サイト改ざん、情報窃取に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(http://mySites.guru / JoomliC) ・概要:http://mySites.guru は、icagenda-batch/1.0 を名乗る自動化された攻撃により、公開フォームから悪意あるファイルがアップロードされ、その後 iCagenda の添付ファイル保存先に配置された PHP ファイルへアクセスする一連の悪用を確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-48939 ・https://www.icagenda.com/ ・https://www.icagenda.com/docs/changelog/icagenda-3-9-15 ・https://www.icagenda.com/docs/changelog/icagenda-4-0-8 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/48xxx/CVE-2026-48939.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 ・https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ ・https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html 🛡CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 Balbooa Forms に存在する、危険なタイプのファイルをアップロードできる脆弱性です。 未認証の攻撃者が実行可能ファイルをアップロードし、フルリモートコード実行につなげられる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月13日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで Balbooa Forms を使用している ・Balbooa Forms 1.0 から 2.4.0 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・公開フォームの添付ファイルアップロード処理が到達可能である ・Balbooa Forms 2.4.1 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者にファイルアップロード機能を悪用される可能性がある ・PHP ファイルを Web ルート配下のアップロードディレクトリへ配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェル、バックドア、不正な管理者アカウント設置、情報窃取に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(http://mySites.guru) ・概要:http://mySites.guru は、Hetzner の abuse report を契機に実環境のアクセスログを確認し、Balbooa Forms のアップロードハンドラに対する POST リクエストが悪用されていたこと、またローカルの Joomla 環境で未認証アップロードから RCE に至る一連の挙動を再現したことを公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-56291 ・https://www.balbooa.com/joomla-forms ・https://github.com/cisagov/vulnrichment/blob/develop/2026/56xxx/CVE-2026-56291.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56291 ・https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirms CVE-2026‑48939 and CVE-2026‑56291 are actively exploited; PoC and exploit code are publicly available, and patches are recommended.

    000636.7K
    44.2K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz #Zafiyet: Balbooa Forms - Yetkisiz Dosya Yükleme (Unrestricted File Upload) CVE Kodu: CVE-2026-56291 Zafiyet Türü: Tehlikeli Türde Dosyanın Kısıtlamasız Yüklenebilmesi (CWE-434) Fidye Yazılımı (Ransomware) Faaliyeti: Bilinmiyor 📌 Zafiyetin Özeti Balbooa Forms üzerinde, tehlikeli dosya türlerinin yüklenmesini kısıtlamayan kritik bir zafiyet tespit edilmiştir. Bu güvenlik açığı, kimliği doğrulanmamış (unauthenticated) saldırganların sisteme rastgele ve çalıştırılabilir (executable) dosyalar yüklemesine olanak tanımakta ve nihayetinde sunucu üzerinde tam yetkili uzaktan kod çalıştırılmasına (full Remote Code Execution - RCE) yol açabilmektedir. 🛠️ Alınması Gereken Aksiyonlar 👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın. 👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin. 👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz dosya yüklemelerini engellemek için gerekli yapılandırmaları sağlayın. 👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.

    Post summary

    CVE‑2026‑56291 allows unauthenticated attackers to upload malicious executables to Balbooa Forms, resulting in full remote code execution; the advisory urges immediate patching or mitigation.

    0204027
    530 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-56291 - critical 🚨 Balbooa Forms &lt; 2.4.1 - Unauthenticated Arbitrary File Upload &gt; Joomla Balbooa Forms contains an unrestricted file upload vulnerability caused by lac... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-56291 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post discloses CVE‑2026‑56291, an unauthenticated arbitrary file upload flaw in Balbooa Forms versions below 2.4.1, and links to a Project Discourse library likely containing a PoC.

    00032423
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Two Joomla CISA KEV zero-days, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), both CVSS 10.0, enable unauthenticated PHP file upload and RCE. #DFIR_Radar https://t.co/wxvHUTXVCQ

    Post summary

    Two Joomla zero‑day vulnerabilities (CVE‑2026‑48939 and CVE‑2026‑56291) with CVSS 10.0 enable unauthenticated PHP file upload and RCE, and are reported by CISA as actively exploited in the wild.

    10010177
    1.8K followersView on X
  • SecAlerts@SecAlertsCo
    Active Exploitation

    🚨 CVE-2026-56291: Actively exploited unauthenticated file upload in Balbooa Forms (Joomla) &lt; 2.4.1 allows uploading executable files for full RCE. CVSS 10. Update immediately. #Joomla #infosec https://secalerts.co/vulnerability/CVE-2026-56291?utm_campaign=x https://t.co/61N7nBtx1F

    Post summary

    The announced CVE-2026-56291 in Balbooa Forms for Joomla is actively exploited and allows unauthenticated file uploads that result in full remote code execution. Immediate remediation is urged.

    00011143
    854 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    10:41 UTC: First exploit attempt in the wild. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56291

    Post summary

    The post reports the first known exploitation attempt for CVE-2026-56291, confirming a PoC/exploit exists, but provides no patching or technical details.

    1000063
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:55 UTC: Thread live on @lyrie_ai. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56291

    Post summary

    A proof‑of‑concept/exploit for CVE-2026-56291 has been discovered, though details about active exploitation, patches, or technical specifics are absent.

    1000065
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:44 UTC: Lyrie Sentinel flagged it. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56291

    Post summary

    A Proof of Concept and exploit have been discovered for CVE-2026-56291, but no active exploitation, patch, or technical details are disclosed.

    1000064
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:41 UTC: CVE-2026-56291 disclosed. A PoC/exploit has been discovered for vulnerability CVE-2026-56291 PT ID: PT-2026-56777 Vendor: Joomla Product: Balboo

    Post summary

    CVE-2026-56291 was disclosed and a PoC/exploit has been discovered, but no active exploitation, patches, detailed technical info, or debunking claims are mentioned.

    1000085
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:52 UTC: GPT-5 enrichment complete. 66 words. 1 citations. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56291

    Post summary

    A proof‑of‑concept or exploit has been discovered for CVE‑2026‑56291, but no further technical details or active exploitation claims are provided.

    1000052
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-56291: A PoC/exploit has been discovered for vulnerability CVE-2026-56291 PT ID: PT-2026-56777 Vendor: Joomla Product: Balbooa Forms extension for Joomla ( Description: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated…

    Post summary

    A proof of concept or exploit has been discovered for CVE-2026-56291 targeting Joomla’s Balbooa Forms extension, but no active exploitation or patch information is provided.

    1000072
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for RCE 2026 exploit Posted: 2026-07-14T07:41:01.000Z Likes: 14 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-56291

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑56291 has been discovered and announced, but no further technical or mitigation details are provided.

    1000084
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    ⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote code execution 0day Intel: 🚨 Two Critical Joomla Flaws Exploited as Zero-Days

    Post summary

    The tweet announces CVE‑2026‑56291, a Balbooa Forms unauthenticated remote‑code‑execution vulnerability, without presenting PoC, exploitation evidence, or mitigation information.

    1000030
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-48939: 🚨 Two Critical Joomla Flaws Exploited as Zero-Days CISA has added two maximum-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: ⚠️ CVE-2026-48939: iCagenda arbitrary file upload ⚠️ CVE-2026-56291: Balbooa Forms unauthenticated remote…

    Post summary

    CISA has listed CVE-2026-48939 (iCagenda arbitrary file upload) in its Known Exploited Vulnerabilities catalog, signaling that the flaw is actively exploited; no proof of concept, exploit code, or patch details are provided.

    1000038
    324 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/07/10:Joomla エクステンション脆弱性 CVE-2026-48939/56291 を KEV に登録 https://iototsecnews.jp/2026/07/13/cisa-warns-of-joomla-sites-running-icagenda-or-balbooa-exploited-in-attacks/ Joomla エクステンションにおける問題は、アップロードされるファイルの形式や種類をサーバ側で適切に検証していないことに起因します。この無制限のファイル・アップロードの脆弱性 CVE-2026-48939/CVE-2026-56291 が悪用されると、攻撃者により実行可能なスクリプト・ファイルが配置され、Web サイトの制御権が奪われてしまう可能性があります。インターネットに公開されているシステムは、常に自動化されたスキャンの脅威にさらされるため、開発や運用の際には、ユーザーから送られてくるファイルを決して信頼せず、拡張子や内容のチェックを徹底する設計が大切になります。 #CISA #CVE202648939 #CVE202656291 #Exploit #Joomla #KEV #PageBuilder #Vulnerability

    Post summary

    The text announces a CISA KEV warning indicating that CVE‑2026‑48939 and CVE‑2026‑56291 are being actively exploited through unrestricted file uploads, but does not provide PoC or exploit code details or patch information.

    01000121
    500 followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Active Exploitation

    🔓 Pentru Joomla, este vorba despre CVE-2026-48939 și CVE-2026-56291, ambele cu scor CVSS v4 de 10 și de tip “Unrestricted File Upload (CWE-434)”. Ambele vulnerabilități au fost confirmate ca fiind exploatate activ și au fost incluse de CISA în

    Post summary

    CVE‑2026‑48939 and CVE‑2026‑56291 are high‑severity Joomla vulnerabilities (Unrestricted File Upload, CVSS v4 10) that have been confirmed as actively exploited, and have been added to the CISA KEV list.

    10000178
    4.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbalbooaforms-joomla\!-

Explore more