DEV Community

Cover image for Over 900 Sangoma FreePBX Instances Compromised via Command Injection Flaw
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Over 900 Sangoma FreePBX Instances Compromised via Command Injection Flaw

Summary

Sangoma FreePBX is under active attack via CVE-2025-64328. Over 900 instances compromised with installed web shells are detected online.

Take Action:

If you use FreePBX, plan a very quick update to version 17.0.3 and make sure your admin panel is isolated from the internet. Your FreePBX is already attacked.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)