Approximately 900 Sangoma FreePBX Systems Compromised via CVE-2025-64328
Article Content
Browse articles
Approximately 900 Sangoma FreePBX systems are compromised due to CVE-2025-64328, a command injection vulnerability. This bug was patched in version 17.0.3, but many systems remain unpatched and vulnerable to exploitation. The vulnerability was added to the CISA KEV list on February 3, 2026, indicating active exploitation.
Ask AI about this cluster
Answers cite the sources they use
Updated 185d ago How this analysis works
Timeline
2025-11-07
CVE-2025-64328 published
2025-11-16
First public PoC released
2026-02-03
CVE-2025-64328 added to CISA KEV (active exploitation)
2026-02-27
Warning issued about ~900 compromised Sangoma FreePBX systems
2026-02-28
Continued warnings about compromised systems
More articles in this cluster (1)
Following this threat?
Track Sangoma and CVE-2025-64328 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…