U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog

2026-07-11T20:51:45Z438e7f938f83e42c381eee6f0d3784a142247455cc4696b144d082bfa39ffe93
AssuranceAmericaBalbooa FormsBlackCatCISAGigaWiperGitHubGo modulesGodDamnINTERPOLKnown Exploited VulnerabilitiesPoisonXU-BootZimbrabootloadercode executiondata breachdriver licensesiCagendalaw enforcementnegotiation compromiseransomwaresecure bootsigned driverstored XSSsupply-chain

What happened

Multiple high-impact security developments: CISA added iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog; Binarly disclosed six U-Boot vulnerabilities (including two that can allow code execution during boot image verification) threatening secure boot on millions of embedded devices; Zimbra released 10.1.19 to fix a critical stored XSS in its Classic Web Client (no CVE assigned yet). Additional notable items: ransomware activity remains elevated (9,291 confirmed attacks since 2018), 222 GitHub repositories were found distributing malware via fake Go packages, a ex

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
438e7f938f83e42c381eee6f0d3784a142247455cc4696b144d082bfa39ffe93
Enrichment time
2026-07-11T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.