FreePBX is a technology platform tracked across 8 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed December 16, 2025; most recent activity May 22, 2026.
A critical vulnerability in FreePBX, tracked as CVE-2026-46376, allows unauthenticated attackers to access user portals via the User Control Panel (UCP). This flaw arises from hard-coded credentials in the userman…
A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
FreePBX has addressed critical vulnerabilities in its Endpoint Manager module that allow for authentication bypass and remote code execution. Discovered by Horizon3.ai researchers, these vulnerabilities affect telephony…
Metasploit has released seven new exploit modules targeting vulnerabilities in FreePBX, Cacti, and SmarterMail. The update includes critical remote code execution capabilities for Cacti and SmarterMail, enhancing tools…
Approximately 900 Sangoma FreePBX systems are compromised due to CVE-2025-64328, a command injection vulnerability. This bug was patched in version 17.0.3, but many systems remain unpatched and vulnerable to…
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised…
Hackers are exploiting a critical vulnerability in FreePBX, specifically CVE-2025-64328, to deploy a persistent webshell named EncystPHP. This attack, attributed to the group INJ3CTOR3, allows complete administrative…