900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
- Posted on February 27, 2026
- By The Hacker News
- 4 Views
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks

Over 900 FreePBX systems remain infected after CVE-2025-64328 exploitation, now listed in CISA KEV amid active attacks.