ZoomEye[verified]@zoomeye_teamDisclosure
The tweet announces a new authenticated command injection vulnerability (CVE‑2025‑64328) in FreePBX’s Endpoint Manager that permits remote code execution; it includes technical details and a CVSS score but does not mention PoCs, exploits, or patches.
yousukezan[verified]@yousukezanActive Exploitation
CVE-2025-64328, a command‑injection flaw in Sangoma FreePBX, is actively exploited in the wild, with attackers deploying a new EncystPHP web shell and maintaining persistence on roughly 900 compromised systems worldwide; a patch is available in version 17.0.3.
Nicolas Krassas[verified]@DinosnActive Exploitation
CVE-2025-64328 is actively exploited, affecting roughly 900 Sangoma FreePBX instances, with no PoC, exploit code, patch, or technical details provided.
FortiGuard Labs[verified]@FortiGuardLabsExploit
The tweet reports that the #EncystPHP web shell is actively exploiting CVE-2025-64328 in FreePBX, highlighting an ongoing malicious use scenario that requires immediate patching.
piyokango[verified]@piyokangoActive Exploitation
CISA confirmed exploitation of four CVEs (CVE‑2025‑40551, CVE‑2019‑19006, CVE‑2025‑64328, CVE‑2021‑39935) and added them to the Known Exploited Vulnerabilities catalog.
kokumօtօ[verified]@__kokumotoActive Exploitation
CVE‑2025‑64328 is actively exploited, with web shells installed on roughly 900 FreePBX instances worldwide, as reported by Shadowserver Foundation.
ThreatSynop[verified]@ThreatSynopActive Exploitation
The post reports that over 900 FreePBX servers remain compromised from CVE‑2025‑64328 exploitation with web shells, urging timely patching and access restrictions to mitigate ongoing attacks.
Machina Record[verified]@MachinaRecordActive Exploitation
The roundup reports several newly disclosed vulnerabilities, including a CVE in OpenClaw that enables AI agent hijacking, a CVE in Gardyn Smart Gardens that could allow remote hacking, and evidence of active exploitation of a CVE in Sangoma FreePBX with 900 infected instances, but no patches or PoC details are provided.