FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
https://thehackernews.com/2025/12/freepbx-authentication-bypass-exposed.html
https://isc.sans.edu/diary/rss/32350
https://www.securityweek.com/sangoma-patches-critical-zero-day-exploited-to-hack-freepbx-servers/
https://thehackernews.com/2025/08/freepbx-servers-targeted-by-zero-day.html
https://securityaffairs.com/181693/hacking/experts-warn-of-actively-exploited-freepbx-zero-day.html
https://github.com/r3vpwnx/CVE-2025-57819
https://github.com/DiegoRivas1/htb-labs-connected
https://github.com/jasonbernier/CVE-2025-5781
https://github.com/TeteREN/CVE-2025-57819-RCE
https://github.com/Jeanback1/exploit-vault
https://github.com/sam910313/cve
https://github.com/Samik-Parajuli/htb-connected-writeup
https://github.com/shunfeng8421/exploit-library
https://github.com/shunfeng8421/security-audit
https://github.com/Its1Zero/cve-2025-57819-exploit
https://github.com/0xyngtg/FreePBX-CVE-2025-57819-CVE-2025-61678
https://github.com/curme-miller/CVE-curme
https://github.com/YuvrajSHAD/FreePBX-CVE-2025-57819
https://github.com/jf-gondim/freepbx-endpoint-sqli-rce
https://github.com/Jeanback1/CVE-2025-57819-exploit
https://github.com/0xEhab/FreePBX-CVE-2025-57819-RCE
https://github.com/ZeroTrustWraith/Exploit-PoC
https://github.com/net-hex/Write-Ups
https://github.com/B1ack4sh/Blackash-CVE-2025-57819
https://github.com/net-hex/CVE-2025-57819
https://github.com/Sucuri-Labs/CVE-2025-57819-ioc-check
https://github.com/rxerium/CVE-2025-57819
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-57819
https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h
https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203
Published: 2025-08-28
Updated: 2026-06-17
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 10
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity: Critical
EPSS: 0.85463
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest