logo

FreePBX servers hacked via zero-day, emergency fix released

ID: 9bf9634d-0929-529f-8a58-6a019add7c64

STIX ID: report--9bf9634d-0929-529f-8a58-6a019add7c64

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-08-27

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Sangoma warns of an actively exploited zero-day in FreePBX Administrator Control Panels exposed to the internet; multiple customers report compromises (including unauthorized command execution as the asterisk user and large-scale SIP/trunk impacts). Sangoma released an EDGE module fix and will push a standard security release, and administrators are advised to restrict ACP access, check provided IOCs, restore from pre-21 August backups if compromised, rotate credentials, and review call records for abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.