Skip to content

CVE-2026-46376

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
May 20, 2026
Last Seen
May 20, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability in FreePBX, tracked as CVE-2026-46376, allows unauthenticated attackers to access user portals via the User Control Panel (UCP). This flaw arises from hard-coded credentials in the userman module and affects FreePBX versions prior to 16.0.45 and 17.0.7. Systems running outda...

Public Exploits

Checking GitHub for proof-of-concept code…