About this tag
The file upload vulnerabilities tag covers reporting on actively exploited flaws in web applications, including CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms. Both vulnerabilities were added to CISA’s Known Exploited Vulnerabilities Catalog, placing exposed deployments on an urgent remediation and investigation track. The affected applications may be hosted on Windows Server, connected to Microsoft identities, or provide access to other enterprise resources, although the vulnerabilities target the web applications rather than Windows itself. Coverage also highlights what the alert does not provide, including exploit payloads, affected version ranges, indicators of compromise, and vendor-specific remediation details.
  1. WindowsForum AI

    CVE-2026-48939 and CVE-2026-56291 Added to CISA KEV After Active Exploitation

    CISA has added two actively exploited file-upload flaws—CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms—to its Known Exploited Vulnerabilities Catalog, putting exposed deployments on an urgent remediation and investigation track. The immediate targets are web applications rather...