Ongoing Web Shell Attacks on Sangoma FreePBX Instances via CVE-2025-64328
Summary
Hide ▲
Show ▼
Over 900 Sangoma FreePBX instances remain compromised with web shells due to the exploitation of CVE-2025-64328, a high-severity command injection vulnerability. The attacks, ongoing since December 2025, have affected instances globally, with the highest concentrations in the U.S., Brazil, Canada, Germany, and France. The vulnerability allows post-authentication command injection, enabling remote access as the asterisk user. The U.S. CISA has added this vulnerability to its KEV catalog, and Fortinet has linked the attacks to the threat actor INJ3CTOR3, who uses a web shell named EncystPHP.
Timeline
-
27.02.2026 19:59 1 articles · 2h ago
CVE-2025-64328 Exploited in Ongoing Attacks on FreePBX Instances
Over 900 Sangoma FreePBX instances remain compromised with web shells due to the exploitation of CVE-2025-64328. The attacks, ongoing since December 2025, have affected instances globally, with the highest concentrations in the U.S., Brazil, Canada, Germany, and France. The U.S. CISA has added the vulnerability to its KEV catalog, and Fortinet has linked the attacks to the threat actor INJ3CTOR3, who uses the EncystPHP web shell.
Show sources
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks — thehackernews.com — 27.02.2026 19:59
Information Snippets
-
CVE-2025-64328 is a high-severity command injection vulnerability with a CVSS score of 8.6.
First reported: 27.02.2026 19:591 source, 1 articleShow sources
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks — thehackernews.com — 27.02.2026 19:59
-
The vulnerability affects FreePBX versions 17.0.2.36 and higher, resolved in version 17.0.3.
First reported: 27.02.2026 19:591 source, 1 articleShow sources
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks — thehackernews.com — 27.02.2026 19:59
-
The attacks have been ongoing since December 2025, with over 900 instances still compromised.
First reported: 27.02.2026 19:591 source, 1 articleShow sources
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks — thehackernews.com — 27.02.2026 19:59
-
The U.S. CISA added CVE-2025-64328 to its KEV catalog earlier this month.
First reported: 27.02.2026 19:591 source, 1 articleShow sources
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks — thehackernews.com — 27.02.2026 19:59
-
The threat actor INJ3CTOR3 has been exploiting the vulnerability to deliver the EncystPHP web shell.
First reported: 27.02.2026 19:591 source, 1 articleShow sources
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks — thehackernews.com — 27.02.2026 19:59