Attackers are actively exploiting CVE-2026-89026, a critical Issabel Framework vulnerability affecting Issabel PBX deployments. A universal hard-coded HS256 JWT signing key in pbxapi/index.php allows unauthenticated remote attackers to forge trusted bearer tokens, call the /pbxapi/manager/originate API endpoint, and abuse Asterisk's System application to execute arbitrary operating-system commands as the Asterisk service account. Shadowserver observed exploitation beginning September 9; VulnCheck assigned the flaw a CVSS v4 score of 9.3 and listed it as known exploited.
Issabel patched the issue by replacing the universal key with one stored in /etc/issabel.conf; organizations should urgently apply the fix associated with commit b97dbaf0b71c1c36f841e672b664afbeb02773bd. Defenders should remove public exposure of PBX APIs and Asterisk management interfaces, restrict access to those services, and investigate affected hosts for anomalous authentication events, originate requests, process or command execution under the Asterisk account, and suspicious outbound network activity.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The Shadowserver Foundation first observed active exploitation of CVE-2026-89026, which allows forged JWT bearer tokens to trigger operating-system command execution through Issabel's Asterisk integration.
Issabel released a patch that replaces the universal hard-coded HS256 JWT signing key with a key stored in /etc/issabel.conf, addressing unauthenticated command execution in the Issabel Framework.
VulnCheck added CVE-2026-89026 to its Known Exploited Vulnerabilities database and rated the flaw 9.3 under CVSS v4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.