Column 1
Skip to content
Column 1

Joomla KEV Alert: Patch Balbooa Forms and iCagenda Today

Joomla KEV patch checklist for Balbooa Forms and iCagenda

July 13, 2026 update: CISA lists both Balbooa Forms and iCagenda Joomla extension issues in its Known Exploited Vulnerabilities catalog. If either extension is installed, treat this as a same-day maintenance task: make a recoverable backup, confirm the extension and Joomla versions, apply a vendor-supported fix or disable the extension, then review the site before reopening normal public workflows.

This guide is intentionally defensive. It explains how site owners, agencies, and hosting teams can inventory, patch, validate, and recover Joomla sites without publishing details that could help someone abuse an affected installation.

What needs attention

Extension CVE What to do
Balbooa Forms CVE-2026-56291 Confirm whether it is installed. Obtain the supported remediation from Balbooa or its authorized support channel; if a verified fixed package is unavailable for the site, disable or remove the extension until the maintenance path is clear.
iCagenda CVE-2026-48939 Update from the vendor's supported package channel. iCagenda's security changelogs identify 3.9.15 and 4.0.8 as security releases for the affected product lines.

CISA added both records to KEV on July 10 with a July 13 remediation due date for covered organizations. For everyone else, KEV status is still the important signal: the extensions need an urgent, documented patch or removal decision rather than a normal deferred plugin-update cycle.

Start with an inventory

  1. Find every Joomla installation. Include production domains, subdomains, old landing pages, staging copies, migrations, and forgotten folders in shared hosting accounts.
  2. Check for both extension names. Record the installed version, whether it is enabled, which sites use it, and whether the site accepts public forms, event submissions, or attachments.
  3. Identify the owner and maintenance path. Confirm who can update the extension, who holds the vendor license if one is required, and whether a theme or custom workflow depends on it.
  4. Do not assume a Joomla core update fixes an extension. Keep Joomla core current, but update or remove the affected extension separately.

Use a backup-first update window

  1. Take a fresh backup of Joomla files, the database, uploaded media, configuration, and the current extension package state.
  2. Keep a short maintenance note with the affected site, owner, backup time, intended change, and rollback contact.
  3. Apply the vendor-supported fixed version where it is available. For iCagenda, verify the maintained release line against the vendor security changelog before changing versions.
  4. For Balbooa Forms, use the vendor's authenticated download or support path to confirm the supported remediation. Do not install an untrusted package from a forum, random mirror, or search result.
  5. If patching must wait, disable the extension and any dependent public workflow rather than leaving an affected component exposed.
  6. Clear Joomla, host, PHP opcode, and CDN caches after the maintenance step so public traffic is not served stale application output.

Verify the site after the change

  • The Joomla administrator can authenticate normally with known authorized accounts.
  • Normal public pages, navigation, and search work without unexpected errors or redirects.
  • Legitimate event, contact, or submission workflows behave as expected after you restore normal service.
  • The updated or removed extension is reflected in the extension inventory and backup/change record.
  • Scheduled tasks, email notifications, integrations, backups, and CDN cache behavior remain normal.

Review before calling the incident closed

Because CISA has flagged active exploitation, version confirmation alone is not enough for a site that had an affected extension enabled. Review recent Joomla administrator activity, changed extension settings, unexpected uploads, unfamiliar scheduled tasks, altered templates, new redirects, and other changes that do not match the site's normal operation. Preserve evidence and involve an experienced cleanup team if you find suspicious changes.

If a shared cPanel, Plesk, or hosting account contains both Joomla and WordPress sites, treat the account as one cleanup boundary. Check the other sites, credentials, backups, and file ownership too. The FixItPhill WordPress support hub is also useful for the WordPress-side backup, maintenance, and post-incident checks that often follow a shared-account review.

Hosting and agency action plan

  • Search managed Joomla inventories for Balbooa Forms and iCagenda, including customers who do not know the extension names.
  • Prioritize public-facing event, form, membership, association, nonprofit, and local-business sites where the extension is active.
  • Tell owners whether the plan is update, disable, remove, or investigate. A clear maintenance notice is better than an unexplained broken form.
  • Keep administration access limited to authorized staff during the maintenance window, and make sure credentials and recovery contacts are current.
  • For CDN-routed sites, retain normal abuse monitoring and temporarily reduce unnecessary public exposure while the origin is patched. Edge controls are not a replacement for the extension fix.

Related FixItPhill guides

Sources

Last reviewed July 13, 2026. This article provides protective maintenance guidance only and does not include reproduction instructions or abuse details.