Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
https://www.securityweek.com/900-sangoma-freepbx-instances-infected-with-web-shells/
https://www.securityweek.com/fresh-solarwinds-vulnerability-exploited-in-attacks/
https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html
https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp