CVE-2019-19006Active Exploitation(sangoma / freepbx)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch sangoma freepbx systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freepbx

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 3 observed days

What's happening

  • Active exploitation reported across 9 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 10 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 6 mentions (2026-02-04); latest day: 1
  • 11 total mentions across 3 days

Affected systems

Vendors
Products
freepbx

Deep dive

Activity timeline11 mentions / 3d
02356Mentions · 2026-02-03: 4Mentions · 2026-02-04: 6Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-04: 1Active Exploitation · 2026-02-03: 3Active Exploitation · 2026-02-04: 5Active Exploitation · 2026-02-12: 1Patch / Workaround · 2026-02-03: 2Patch / Workaround · 2026-02-04: 4Technical Details · 2026-02-03: 4Technical Details · 2026-02-04: 5Technical Details · 2026-02-12: 102-0302-0402-12
Signal classification3 categories
Active Exploitation
981.8%
Disclosure
19.1%
General
19.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-034
Active Exploitation3Disclosure1
2026-02-046
Active Exploitation5General1
2026-02-121
Active Exploitation1
Full discourse11 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 4 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Post summary

    The tweet announces that CISA has added four CVEs to its KEV Catalog, providing only short vulnerability descriptions without any PoC, exploit details, or patch information.

    1401863.7K
    164.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/3追加) 🛡️No.1503 CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / SolarWinds CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / SolarWinds) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホストマシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 🛡️No.1504 CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、パスワード認証を回避し、FreePBX管理者が提供するサービスにアクセスされる恐れがあります。 https://iki.freepbx.org/display/FOP/2019-11-20%2BRemote%2BAdmin%2BAuthentication%2BBypass 🛡️No.1505 CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability ============= CVSSスコア: 8.6 (Base) / GitHub, Inc. CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:OSコマンドインジェクション (CWE-78 / GitHub, Inc.) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、testconnection -> check_ssh_connect()関数を介してコマンドインジェクションをされる恐れがあります。この脆弱性を利用して、asteriskユーザーとしてシステムへのリモートアクセスを取得される可能性があります。 https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw 🛡️No.1506 CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability ============= CVSSスコア: 6.8 (Base) / GitHub, Inc. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / GitHub, Inc.) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、CI Lint API を介してサーバーサイドリクエストを実行される恐れがあります。 https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed exploitation of four CVEs and added them to its KEV catalog, while providing vendor advisories, CVSS details, and remediation links.

    010604.0K
    42.5K followersView on X
  • hiro_@papa_anniekey
    General

    KEV追加 CVE-2019-19006 Sangoma FreePBX CVE-2021-39935 GitLab Community and Enterprise Editions CVE-2025-40551 SolarWinds Web Help Desk CVE-2025-64328 Sangoma FreePBX

    Post summary

    The tweet announces the addition of several CVEs to the KEV list, naming affected products but offering no further technical or exploit details.

    00041681
    6.0K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/02/03:SolarWinds Web Help Desk/GitLab/Sangoma FreePBX の脆弱性を登録 https://iototsecnews.jp/2026/02/04/u-s-cisa-adds-solarwinds-web-help-desk-sangoma-freepbx-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog/ CISA KEV に、SolarWinds Web Help Desk/GitLab/Sangoma FreePBX の脆弱性が登録されました。1 つ目の SolarWinds の CVE-2025-40551 は、プログラムがデータを取り込む際の検証不足により、悪意ある命令を実行してしまう問題があります。2 つ目の GitLab の CVE-2021-39935 は、外部からの不正なリクエストを、サーバが内部向けに送信してしまうという、設定の不備に起因するものです。また、Sangoma FreePBX では、ログイン画面を素通りできてしまう認証の脆弱性 CVE-2019-19006 と、管理操作の裏側でOSへの直接命令が紛れ込む脆弱性 CVE-2025-64328 が悪用されています。これらの脆弱性は、いずれも攻撃者に対してサーバのコントロールを許し得るものであり、実際に悪用が確認されたことで、CISA が警告を発する事態となっています。 #CISA #CVE201919006 #CVE202139935 #CVE202540551 #CVE202564328 #Exploit #FreePBX #GitLab #Government #KEV #SolarWinds #Vulnerability

    Post summary

    CISA has added four CVEs to its KEV catalog after confirming active exploitation, but no PoC, exploit code, or patch details are provided in the text.

    01000150
    483 followersView on X
  • BotBauR@BotBauR
    Active Exploitation

    KEV de CISA (explotadas): SolarWinds Web Help Desk CVE-2025-40551 (RCE) + FreePBX CVE-2019-19006 (auth bypass) y CVE-2025-64328 (cmd inj). Si en MX lo operas, prioriza parche/mitigación hoy. https://www.cisa.gov/known-exploited-vulnerabilities-catalog #Ciberseguridad #Mexico

    Post summary

    CISA lists SolarWinds Web Help Desk CVE‑2025‑40551, FreePBX CVE‑2019‑19006, and CVE‑2025‑64328 as actively exploited; the post urges immediate patching or mitigation in Mexico.

    0001063
    87 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 3) CVE-2019-19006 Sangoma FreePBX の不適切な認証の脆弱性 CVE-2021-39935 GitLab Community および Enterprise エディションのサーバーサイドリクエストフォージェリ (SSRF) 脆弱性 CVE-2025-40551 SolarWinds Webヘルプデスクにおける信頼できないデータのデシリアライゼーションの脆弱性 CVE-2025-64328 Sangoma FreePBX OS コマンドインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA identified four CVEs that are already being exploited, including vulnerabilities in Sangoma FreePBX and SolarWinds. No PoC, exploit code, or patch details are provided in the announcement.

    00010297
    4.7K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2019-19006  Sangoma FreePBX の不適切な認証の脆弱性 CVE-2021-39935  GitLab Community および Enterprise エディションのサーバーサイドリクエストフォージェリ (SSRF) 脆弱性 他2件

    Post summary

    CISA has announced four known exploited vulnerabilities, including authentication and SSRF weaknesses, but the notice lacks PoC details, exploit code, or patch information.

    00000110
    45 followersView on X
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2019-19006: FreePBX Authentication Bypass Alert 🚨 Sangoma An authentication bypass vulnerability has been disclosed in FreePBX, allowing unauthenticated attackers to gain full administrative access. Active exploitation has been observed and a public proof of concept is available. Risk Severity: Critical CVSS 9.8. Public exploit and active attacks targeting internet-facing FreePBX installations. Impact: Complete administrative control of FreePBX web interface. Modification of dial plans and call routing. Voicemail access and potential interception of calls. Toll fraud and financial loss. Network pivoting into internal systems via Asterisk integration. Root Cause: CWE-287, Improper Authentication. The AJAX request handler in /admin/ajax.php fails to enforce session validation on certain BMO module calls, allowing unauthenticated command execution. Attackers can: Send crafted POST requests to /admin/ajax.php without authentication. Bypass session checks and execute administrative commands. Alter configuration, intercept communications, and enable fraudulent activity. Are You Affected? Vulnerable: FreePBX 15 ≤ 15.0.16.26, 14 ≤ 14.0.13.11, 13 ≤ 13.0.197.13 Fixed: FreePBX 15.0.16.27, 14.0.13.12, 13.0.197.14 or later Immediate Action Required: Update FreePBX to the latest patched version immediately. Restrict /admin/ access to trusted IPs and disable internet-facing management. Deploy WAF rules to block unauthenticated BMO POST requests. Audit logs for suspicious access, isolate compromised systems, and reset all credentials. Unauthenticated FreePBX access is a full compromise. Patch now to prevent fraud and internal network takeover 🛡️ #ostorlabCVE

    Post summary

    FreePBX authentication bypass CVE-2019-19006 is actively exploited; a public PoC exists, CVSS 9.8, and vendors must patch immediately.

    0000095
    582 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA flags actively exploited SolarWinds Web Help Desk RCE (CVE-2025-40551) and adds more flaws to KEV CISA added SolarWinds Web Help Desk’s unauthenticated deserialization RCE (CVE-2025-40551, CVSS 9.8) to the Known Exploited Vulnerabilities catalog, noting active exploitation and urging immediate upgrade to WHD 2026.1. KEV also added FreePBX (CVE-2019-19006, CVE-2025-64328) and GitLab SSRF (CVE-2021-39935), with federal remediation deadlines of Feb 6 and Feb 24, 2026. 🎯 Target: Global/IT Service Management & VoIP #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html

    Post summary

    CISA has listed CVE‑2025‑40551 as actively exploited in its KEV catalog and is urging users to upgrade to WHD 2026.1 to mitigate the unauthenticated deserialization RCE.

    0000036
    192 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA adds SolarWinds Web Help Desk + FreePBX + GitLab flaws to KEV with urgent deadlines CISA added four actively exploited vulnerabilities to the KEV catalog—SolarWinds Web Help Desk deserialization RCE (CVE-2025-40551), GitLab SSRF (CVE-2021-39935), and two Sangoma FreePBX issues (CVE-2019-19006 auth bypass; CVE-2025-64328 authenticated OS command injection)—forcing rapid patching/mitigations to prevent takeover of helpdesk/VoIP infrastructure. FCEB agencies must fix the SolarWinds flaw by Feb 6, 2026 and the others by Feb 24, 2026, signaling real-world exploitation risk for any exposed deployments. 🎯 Target: Global/ITSM & VoIP (SolarWinds WHD, FreePBX, GitLab) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/187592/security/u-s-cisa-adds-solarwinds-web-help-desk-sangoma-freepbx-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA identified four actively exploited vulnerabilities in SolarWinds Web Help Desk, GitLab, and FreePBX, adding them to the KEV catalog and imposing tight patch deadlines to curb real‑world takeover risks.

    0000074
    192 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA adds SolarWinds Web Help Desk + FreePBX + GitLab flaws to KEV with urgent deadlines CISA added four actively exploited vulnerabilities to the KEV catalog—SolarWinds Web Help Desk deserialization RCE (CVE-2025-40551), GitLab SSRF (CVE-2021-39935), and two Sangoma FreePBX issues (CVE-2019-19006 auth bypass; CVE-2025-64328 authenticated OS command injection)—forcing rapid patching/mitigations to prevent takeover of helpdesk/VoIP infrastructure. FCEB agencies must fix the SolarWinds flaw by Feb 6, 2026 and the others by Feb 24, 2026, signaling real-world exploitation risk for any exposed deployments. 🎯 Target: Global/ITSM & VoIP (SolarWinds WHD, FreePBX, GitLab) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/187592/security/u-s-cisa-adds-solarwinds-web-help-desk-sangoma-freepbx-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA has added four actively exploited vulnerabilities to its KEV catalog, stressing real-world exploitation risk and urging rapid patching with specific deadlines.

    0000075
    192 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafreepbx---

Explore more