FreeSWITCH released fixes in v1.11.1 for two critical pre-authentication heap buffer overflow vulnerabilities that could crash exposed voice servers and may enable remote code execution. The most severe issue, CVE-2026-49841 (CVSS 9.8), affects the mod_verto HTTP request handler: affected versions before 1.11.1 allocate a fixed 2 MiB buffer for application/x-www-form-urlencoded POST bodies while accepting a Content-Length of nearly 10 MiB, allowing an attacker to overflow the heap by roughly 8 MiB over the network before HTTP basic authentication is checked.
A second flaw, CVE-2026-49840 (CVSS 9.1), affects the libesl library, where esl_recv_event() uses atol() to parse Content-Length and passes the result to malloc() without final validation, creating a path to memory corruption or denial of service through negative values. Although no public exploit was reported, both bugs were described as easy to trigger, prompting guidance to upgrade immediately to FreeSWITCH v1.11.1, restrict Verto and ESL access to trusted networks, remove Verto vhost entries, disable mod_verto if it is not needed, and isolate the control-plane network.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry, CVE-2026-49841, was published describing a network-reachable pre-authentication heap buffer overflow in FreeSWITCH mod_verto. The disclosure assigned a CVSS 9.8 severity and linked the issue to the FreeSWITCH fix in version 1.11.1.
FreeSWITCH patched the pre-authentication heap buffer overflow in the mod_verto HTTP request handler in version 1.11.1. The flaw affects versions prior to 1.11.1 and can overflow a fixed 2 MiB heap buffer via an oversized POST body before authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.