logo

900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks

ID: 418793ba-d377-5abc-af46-f63a9bc6fdf8

STIX ID: report--418793ba-d377-5abc-af46-f63a9bc6fdf8

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Shadowserver and Fortinet report that adversaries have been actively exploiting CVE-2025-64328 in FreePBX (CVSS 8.6) since December 2025 to deploy the EncystPHP web shell, resulting in over 900 compromised instances globally (401 in the U.S.). The flaw permits post-authentication command injection allowing an attacker to execute arbitrary shell commands as the asterisk user and enable outbound PBX call activity; FreePBX released a fix in 17.0.3 and CISA added the vulnerability to its KEV catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.