logo

FreePBX RCE Vulnerabilities Threaten Telecom Servers

ID: 6bac3bc8-1fe8-5abe-aa99-02a2948a64ec

STIX ID: report--6bac3bc8-1fe8-5abe-aa99-02a2948a64ec

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

FreePBX disclosure: two critical authenticated vulnerabilities (CVSS 8.6) affecting the Superfecta module (arbitrary PHP inclusion leading to RCE) and the UCP interface (authenticated command injection) can allow attackers to execute code as the web server and fully compromise VoIP hosts; administrators are advised to apply provided patches and restrict access to ACP/UCP immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.