Back X Rishi on X: " Earlier today, I reported a critical vulnerability in the Issabel Framework (CVE ...
Rishi @rxerium 🚨 Earlier today, I reported a critical vulnerability in the Issabel Framework (CVE‑2026‑89026), rated CVSS 9.8 with early signs of exploitation in the wild. The vulnerability involves a hard-coded JWT signing key that allows unauthenticated attackers to forge tokens and ultimately achieve RCE on the underlying Asterisk system. It carries a CVSS score of 9.8 and has already been observed being exploited in the wild by The Shadowserver Foundation ( @ shadowserver ) as of 09/09. Thank you to @ VulnCheck for the smooth collaboration throughout the CNA process. More details: cve.org/CVERecord?id=C… 6:03 PM · Sep 15, 2026 4,922 Views 3
Simo @SimoKohonen 4h 💪💪💪 1
Xanagement @Xanagement 2h 😳
Anthony @HoustonIntrove1 3h A hard-coded JWT signing key is game over for auth—unauthenticated forge = admin if the app trusts the token. With CVSS 9.8 and early wild activity, I'd patch, rotate that key, and hunt sessions issued before the fix on any exposed Issabel.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
