#7
SecurityWeek
general
February 27, 2026 at 13:24 UTC
900 Sangoma FreePBX Instances Infected With Web Shells
By Ionut Arghire
AI Summary
Attackers infected 900 Sangoma FreePBX instances with web shells by exploiting a post-authentication command injection vulnerability in the endpoint manager's interface. The widespread compromise of these business phone system servers creates persistent backdoor access for attackers in corporate networks.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →