CiberLATAMbywhalemate

#Balbooa Forms

This tag brings together reporting on findings, alerts, and analysis tied to a forms plugin for websites that can surface in exposure cases, feature abuse, or misconfiguration reviews. It collects material relevant to security teams, site administrators, and readers tracking the attack surface of widely used platforms across Latin America.

CVE-2026-56291 hits Balbooa Forms on Joomla

Balbooa Forms for Joomla had a critical RCE abused as a zero-day. Patch 2.4.1 landed July 9, and CISA added it to KEV.

Jul 15, 2026 · 3 min