Product of Sangoma

FreePBX

As of , 3 Sangoma FreePBX vulnerabilities are on CISA's list of exploited vulnerabilities; 2 were added in 2026. Patch first: CVE-2025-64328.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-64328OS Command InjectionSangoma FreePBXPatch this weekMetasploit module; EPSS 0.850.85
2CVE-2025-57819Authentication BypassSangoma FreePBXPatch this weekMetasploit module; EPSS 0.850.85
3CVE-2019-19006Improper AuthenticationSangoma FreePBXPatch this weekEPSS 0.560.56

Added each year

0.511.522025: 1120252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20251
20262

Used in ransomware