CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds Two Known Exploited Vulnerabilities to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2354

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two file upload vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. These vulnerabilities allow unrestricted uploads of dangerous file types and represent a common attack vector. Federal agencies must prioritize patching under Binding Operational Directive 26-04, which requires rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.

Why it matters: Federal agencies must treat these two vulnerabilities as critical priorities for remediation on exposed systems; organizations running iCagenda or Balbooa Forms should verify whether these file upload flaws have been exploited before patching and conduct incident investigation if compromise occurred.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two file upload vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. These vulnerabilities allow unrestricted uploads of dangerous file types and represent a common attack vector. Federal agencies must prioritize patching under Binding Operational Directive 26-04, which requires rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.

Why it matters: Federal agencies must treat these two vulnerabilities as critical priorities for remediation on exposed systems; organizations running iCagenda or Balbooa Forms should verify whether these file upload flaws have been exploited before patching and conduct incident investigation if compromise occurred.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary