Skip to content
900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation

900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation

First seen 1 Mar 2026, 12:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised since attacks began in December 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 185d ago How this analysis works

Timeline

2025-11-07
CVE-2025-64328 published
2025-11-16
First public PoC released
2025-12-01
Attacks on Sangoma FreePBX instances began
2026-02-03
CVE-2025-64328 added to CISA KEV for active exploitation
2026-03-01
900 Sangoma FreePBX systems reported infected

More articles in this cluster (5)

Following this threat?

Track APT41, EncystPHP and Sangoma in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed