News Security CISA flags active RCE exploitation in Joomla extensions; separate SQLi fix lands for Quix Page Builder July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment CISA added two actively exploited Joomla extension flaws to its KEV catalog, warning of RCE via file uploads in iCagenda and Balbooa Forms. Separately, Quix Page Builder patched an unauthenticated SQL injection in version 6.2.1. Read more » CISA CMS security cve Joomla Joomla extensions Patch management Remote code execution
News CVE-2026-9082: Drupal’s PostgreSQL SQL injection is being probed — update your sites May 30, 2026 / May 30, 2026 by Alex Mira | Leave a Comment Drupal disclosed CVE-2026-9082, a PostgreSQL-only SQL injection in core. Exploit attempts are being observed. Update to the patched Drupal releases as soon as possible. Read more » CMS security CVE-2026-9082 Drupal Patching PostgreSQL SQL injection vulnerability