logo

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Commands and Hijack Admin Accounts

ID: 6171d5e2-ab2c-5f90-9020-16e8c14cfe8f

STIX ID: report--6171d5e2-ab2c-5f90-9020-16e8c14cfe8f

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Tamilselvan

...
...

Sangoma released fixes for two critical FreePBX vulnerabilities: an unauthenticated RCE in the UCP Node socket.io implementation and an SQL injection in the missedcall module that can be triggered via SIP Caller ID; both are rated CVSS 9.3 and can lead to full admin takeover on internet-facing FreePBX 16/17 systems, so administrators are urged to patch immediately and apply mitigations (Responsive Firewall, restrict inbound SIP, enable MFA/SAML, deploy SBCs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.