Zero-Day Exploits Hit Joomla Extensions iCagenda and Balbooa Forms, Prompting Urgent Patching

Zero-Day Exploits Hit Joomla Extensions iCagenda and Balbooa Forms, Prompting Urgent Patching

Attackers are actively exploiting critical vulnerabilities in the popular Joomla extensions iCagenda and Balbooa Forms, enabling site takeovers through arbitrary code execution and file manipulation.

Two widely used Joomla extensions—iCagenda, an event management component, and Balbooa Forms, a form builder—have been found to contain critical security flaws that are being actively exploited in the wild as zero-days. According to security researchers, the vulnerabilities allow unauthenticated attackers to execute arbitrary PHP code on the underlying server and modify or delete arbitrary files, effectively giving them full control over affected Joomla sites.

The flaws stem from insufficient input validation in key functions, which permits malicious actors to inject and run commands without requiring any authentication. Because both extensions are popular among businesses, nonprofits, and community sites for managing events and collecting user data, the attack surface is substantial. Exploitation attempts have been detected on a significant number of installations, and the attacks appear to be highly automated, scanning the web for vulnerable versions.

Website owners using iCagenda or Balbooa Forms are strongly urged to check their extension versions immediately and apply the latest updates released by the developers. Both vendors have issued patches that remediate the issues, but delaying updates leaves sites exposed. As a stopgap, administrators can temporarily disable the extensions until patching is completed, though this may disrupt site functionality. Additionally, reviewing server logs for unusual POST requests or unexpected file modifications can help identify if a breach has already occurred.

This incident highlights the critical need for proactive vulnerability management and rapid patch deployment in web hosting environments. Even a single outdated extension can serve as an entry point for attackers. For organizations running Joomla, ensuring they have robust security practices in place is critical; services like AEU-I can provide the security-first infrastructure and expert guidance needed to keep such sites protected without relying solely on internal patch cycles.