900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
ID: 418793ba-d377-5abc-af46-f63a9bc6fdf8
STIX ID: report--418793ba-d377-5abc-af46-f63a9bc6fdf8
Feed Name: The Hacker News
Shadowserver and Fortinet report that adversaries have been actively exploiting CVE-2025-64328 in FreePBX (CVSS 8.6) since December 2025 to deploy the EncystPHP web shell, resulting in over 900 compromised instances globally (401 in the U.S.). The flaw permits post-authentication command injection allowing an attacker to execute arbitrary shell commands as the asterisk user and enable outbound PBX call activity; FreePBX released a fix in 17.0.3 and CISA added the vulnerability to its KEV catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
