logo

CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances

ID: d5656333-121b-5c70-9c48-5c20210d0871

STIX ID: report--d5656333-121b-5c70-9c48-5c20210d0871

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-03-01

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Active exploitation of CVE-2025-64328 in Sangoma FreePBX** led to the deployment of the EncystPHP web shell across roughly 900 systems worldwide; attackers exploited a post-authentication command-injection in the Endpoint Manager to achieve remote command execution, create persistent root access (including SSH key injection and new users), harvest credentials, remove logs and competing shells, and deploy additional payloads — activity attributed to INJ3CTOR3 and tracked by Shadowserver, FortiGuard, and CISA (added to KEV).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.