FreePBX Security Advisory AV26-818 Warns of Vulnerabilities in Multiple Products

Published:

spot_img

Advisory Number: AV26-818
Date Issued: August 14, 2026

FreePBX has issued a security advisory regarding vulnerabilities affecting several of its products. As of August 13, 2026, the following components are identified as vulnerable:

  • Backup
    • Versions: After or equal to 17.0.5.34, Prior to 17.0.11
  • Framework
    • Versions: After or equal to 17.0.1, Prior to 17.0.30
    • Prior to 16.0.47
  • Missed Call
    • Versions: After or equal to 17.0.1, Prior to 17.0.4
    • Prior to 16.0.11
  • Music
    • No specific versions listed.
  • Text-to-Speech (TTS)
    • Versions: After or equal to 17.0.1, Prior to 17.0.5.4
    • Prior to 16.0.6
  • User Control Panel (UCP)
    • No specific versions listed.

The Cyber Centre strongly advises users and administrators to review the details of this advisory and apply the necessary updates to mitigate potential risks. For further information and guidance, please refer to the official advisory at the Cyber Centre’s website.

It is crucial for organizations utilizing FreePBX to ensure that they are running the latest versions of the affected products to protect against potential vulnerabilities. Regular updates and security patches are essential components of a robust cybersecurity strategy.

Readers can also explore current and upcoming editions through the Cyber Warriors Middle East Resources section.

spot_img

Related articles

Recent articles

Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign

Lazarus Group's Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign In early 2026, Check Point Research began tracking a significant wave of cyberattacks under...

DeadLock Ransomware Leverages Polygon Smart Contracts for Enhanced Extortion Resilience

The ransomware group known as DeadLock has been observed utilizing decentralized infrastructure to enhance victim communications and data leak operations, thereby improving operational resilience....

Jaguar Land Rover Faces Sales Decline Amid Middle East Conflict and Cyber Attack Recovery Challenges

Jaguar Land Rover (JLR) is facing significant challenges in its recovery efforts following a cyber attack last year, compounded by ongoing geopolitical tensions in...

Threat Actors Exploit Microsoft SharePoint CVE-2026-55040 Authentication Bypass Following PoC Release

Threat actors are actively exploiting a newly disclosed vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the release of a proof-of-concept (PoC) code. This...