Securityaffairs 900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation
Article Content
Browse articles
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised since attacks began in December 2025.
Ask AI about this cluster
Answers cite the sources they use
Updated 185d ago How this analysis works
Timeline
2025-11-07
CVE-2025-64328 published
2025-11-16
First public PoC released
2025-12-01
Attacks on Sangoma FreePBX instances began
2026-02-03
CVE-2025-64328 added to CISA KEV for active exploitation
2026-03-01
900 Sangoma FreePBX systems reported infected
More articles in this cluster (5)
Following this threat?
Track APT41, EncystPHP and Sangoma in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE, and EPA…