Signal
900+ Sangoma FreePBX instances compromised in ongoing web shell attacks
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-02-27 13:24 UTCUpdated 2026-02-27 17:59 UTC
rss
securitysangoma_freepbx_instances
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Recent attacks have compromised over 900 Sangoma FreePBX instances, exploiting a post-authentication command injection vulnerability. The Shadowserver Foundation reported that these web shell infections began in December 2025 and continue to affect systems globally. Notably, 401 of the infected instances are located in the U.S., with others in Brazil, Canada, Germany, and France. This ongoing threat highlights the importance of securing communication systems against such vulnerabilities.
Score total
1.02
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The attacks have been ongoing since December 2025, with new infections reported recently.
- The geographical distribution of the infected instances raises concerns about global cybersecurity.
- Immediate awareness can prompt organizations to secure their systems against similar vulnerabilities.
Why it matters
- The ongoing infections indicate a significant security vulnerability in communication systems.
- The widespread nature of the attacks highlights the need for improved security measures.
- Understanding these incidents can help organizations mitigate similar threats in the future.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- Over 900 Sangoma FreePBX instances have been infected with web shells due to a command injection vulnerability.
How sources frame it
- Security Analysts: neutral
All evidence
All evidence
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
thehackernews · thehackernews.com · 2026-02-27 17:59 UTC
900 Sangoma FreePBX Instances Infected With Web Shells
SecurityWeek · securityweek.com · 2026-02-27 13:24 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- thehackernews (1)
- SecurityWeek (1)
Top origin domains (this list)
- thehackernews.com (1)
- securityweek.com (1)