The Asterisk Development Team released patched versions 20.20.1, 21.12.3, 22.10.1, 23.4.1, and certified build 22.8-cert3 to address 19 to 20 security advisories across the telephony platform. The fixes span ARI, PJSIP, H.323, XMPP, LDAP, HTTP, SMS handling, Codec2, OGG/Speex playback, logging utilities, and other components, covering buffer overflows, out-of-bounds reads and writes, use-after-free, SQL and LDAP injection, reflected XSS, null pointer dereference, privilege escalation, information disclosure, and conditional remote code execution. Asterisk also added ACL support for the built-in HTTP server and ARI in some branches and changed ARI behavior so dangerous dialplan functions now require live_dangerously to be enabled in asterisk.conf.
Notable issues included an ARI REST-over-WebSocket authorization bypass that could let a read-only user load arbitrary module paths and potentially reach conditional RCE, an ARI setChannelVar flaw that bypassed live_dangerously protections and permitted write-capable dialplan functions such as FILE(), and an ast_loggrabber weakness that could execute a Python script from a world-writable /tmp location, leading to privilege escalation and possible RCE. Additional advisories covered an unauthenticated AMI-over-HTTP digest authentication null-pointer dereference that could crash exposed systems, a crafted UNISTIM DIALPAGE packet that could overflow phone_number and crash Asterisk, a malformed OGG/Speex audio file that could trigger a heap overflow and denial of service, and a T.140 RED heap overflow in deprecated chan_sip that could allow an authenticated attacker to crash Asterisk or potentially execute code under specific configurations.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-25, Asterisk published GitHub security advisories detailing multiple flaws, including a UNISTIM out-of-bounds write, an AMI HTTP digest-auth NULL dereference, an OGG/Speex heap overflow, a T.140 RED heap overflow, and an ARI setChannelVar live_dangerously bypass. The advisories identified affected versions and mapped fixes to the newly released patched branches.
On 2026-06-25, the Asterisk Development Team released security updates 20.20.1, 21.12.3, 22.10.1, 23.4.1, and certified-22.8-cert3. The releases addressed 19-20 security advisories across multiple components and included changes such as stricter ARI handling and, on some branches, added ACL support for the built-in HTTP server and ARI.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourcedownloads.asterisk.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.