FreePBX security advisory (AV26-680)
Serial number: AV26-680 Date: July 9, 2026 On July 9, 2026, FreePBX published security advisories to address vulnerabilities in the following products: FreePBX API (FreePBX 17) – versions prior to 17.0.9 FreePBX Backup (FreePBX 17) – versions prior to 17.0.11 The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations. Authenticated API generatedocs Host Command Injection Authenticated Arbitrary SSH Key Injection via Backup Module FreePBX Security Advisories
CSIRTS triage
- What
- Multiple vulnerabilities have been identified in FreePBX that could allow command injection and SSH key injection.
- Who is affected
- Users of FreePBX 17 versions prior to 17.0.9 and 17.0.11 are affected.
- Urgency
- Remediation is necessary to prevent potential exploitation of these vulnerabilities.
- Action
- Users should update to the latest versions of FreePBX.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreePBX
Get an email when a new FreePBX advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-680
More from Canadian Centre for Cyber Security
- unknownJFrog security advisory (AV26-867) – Update 12026-09-02
- unknownSonicWall security advisory (AV26-872) – Update 12026-09-02
- unknownProgress Software security advisory (AV26-875)2026-09-02
- unknownGoogle security advisory (AV26-874)2026-09-02
- unknownHPE security advisory (AV26-873)2026-09-02