Image for Article: 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks

Article Details

Title
Article: 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
Impact Score
6 / 10
AI Summary (Processed Content)

Over 900 Sangoma FreePBX instances remain infected with web shells due to exploitation of a high-severity command injection vulnerability, CVE-2025-64328. The U.S. has the most compromised systems, and the flaw allows authenticated attackers to execute arbitrary commands on the host. The vulnerability is being actively exploited, including by a threat actor known as INJ3CTOR3, prompting urgent recommendations to update software and restrict administrative access.

Original URL
https://thehackernews.com/2026/02/900-sangoma-freepbx-instances.html
Source Feed
The Hacker News
Published Date
2026-02-27 17:59
Fetched Date
2026-03-04 13:39
Processed Date
2026-03-04 13:58
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content