The Canadian Centre for Cyber Security issued advisory AV26-818 warning that multiple FreePBX components contain vulnerabilities requiring immediate updates. Affected modules include backup, framework, missedcall, music, tts, and ucp across FreePBX 16 and 17 branches, with the notice directing administrators to review FreePBX's published security advisories and apply patched releases.
The most severe flaws include CVE-2026-73665, an unauthenticated remote code execution bug in UCP caused by a Socket.IO namespace authentication bypass and AMI action injection, fixed in UCP 17.0.9, and CVE-2026-73663, an unauthenticated SQL injection in missedcall via inbound Caller ID name that can enable administrator takeover, fixed in missedcall 16.0.11 and 17.0.4. Additional high-severity issues include CVE-2026-73664 in the Backup module, which can inject an SSH key into authorized_keys for persistent shell access and is fixed in Backup 17.0.11, and CVE-2026-73661 in the Framework module, where a crafted backup can restore AUTHTYPE=none and weaken authentication, fixed in Framework 16.0.47 and 17.0.30.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On August 14, 2026, the Canadian Centre for Cyber Security published security notice AV26-818 covering multiple FreePBX vulnerabilities and urging users to review vendor guidance and apply updates.
The Canadian Centre for Cyber Security stated that as of August 13, 2026, multiple FreePBX modules were affected, including backup, framework, missedcall, music, tts, and ucp. The notice identified impacted version ranges across FreePBX 16 and 17 branches and directed administrators to FreePBX advisories for remediation.
On August 13, 2026, GitHub Security Advisories received CVE records for FreePBX vulnerabilities affecting Backup, Framework, UCP, and missedcall. The records correspond to CVE-2026-73664, CVE-2026-73661, CVE-2026-73665, and CVE-2026-73663.
On July 16, 2026, FreePBX published five GitHub security advisories covering a critical unauthenticated UCP remote code execution flaw, a critical unauthenticated missedcall SQL injection flaw, and high-severity issues in TTS, Framework, and Music.
On July 9, 2026, FreePBX published GitHub security advisories for an API generatedocs host command injection flaw and an authenticated arbitrary SSH key injection issue in the Backup module.
On June 12, 2026, FreePBX published GitHub security advisories for Superfecta arbitrary PHP code execution, Backup module path traversal remote code execution, and Soundlang remote code execution via file upload and convert.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.