FreePBX security advisory (AV26-818)
Serial number: AV26-818 Date: August 14, 2026 As of August 13, 2026, FreePBX is affected by vulnerabilities in the following products: backup After or equal to 17.0.5.34, Prior to 17.0.11 framework After or equal to 17.0.1, Prior to 17.0.30 Prior to 16.0.47 missedcall After or equal to 17.0.1, Prior to 17.0.4 Prior to 16.0.11 music Prior to 17.0.7 tts After or equal to 17.0.1, Prior to 17.0.5.4 Prior to 16.0.6 ucp Prior to 17.0.9 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. FreePBX Security Advisories
CSIRTS triage
- What
- Multiple unspecified vulnerabilities affect several FreePBX modules.
- Who is affected
- FreePBX deployments running the affected module versions listed above.
- Urgency
- Moderate; no CVE details or active exploitation reported, but multiple modules across major versions are affected.
- Action
- Apply updates to all affected modules to the specified patched versions immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreePBX
Get an email when a new FreePBX advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-818
More from Canadian Centre for Cyber Security
- unknownHashiCorp security advisory (AV26-817)2026-08-14
- unknownZimbra security advisory (AV26-816)2026-08-14
- unknownWebPros security advisory (AV26-815)2026-08-13
- unknownGitLab security advisory (AV26-814)2026-08-13
- unknownAMD security advisory (AV26-813)2026-08-13