CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

FreePBX security advisory (AV26-818)

unknown
Serial number: AV26-818 Date: August 14, 2026 As of August 13, 2026, FreePBX is affected by vulnerabilities in the following products: backup After or equal to 17.0.5.34, Prior to 17.0.11 framework After or equal to 17.0.1, Prior to 17.0.30 Prior to 16.0.47 missedcall After or equal to 17.0.1, Prior to 17.0.4 Prior to 16.0.11 music Prior to 17.0.7 tts After or equal to 17.0.1, Prior to 17.0.5.4 Prior to 16.0.6 ucp Prior to 17.0.9 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. FreePBX Security Advisories

CSIRTS triage

vendor: FreePBXproduct: FreePBXOtheraffected: backup 17.0.5.34–17.0.10, framework 17.0.1–17.0.29 and prior to 16.0.47, missedcall 17.0.1–17.0.3 and prior to 16.0.10, music prior to 17.0.6, tts 17.0.1–17.0.5.3 and prior to 16.0.5, ucp prior to 17.
What
Multiple unspecified vulnerabilities affect several FreePBX modules.
Who is affected
FreePBX deployments running the affected module versions listed above.
Urgency
Moderate; no CVE details or active exploitation reported, but multiple modules across major versions are affected.
Action
Apply updates to all affected modules to the specified patched versions immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FreePBX

Get an email when a new FreePBX advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-818

More from Canadian Centre for Cyber Security