The Containment Era is here. →Explore

Executive Summary

In early 2026, over 900 Sangoma FreePBX instances were compromised through the exploitation of a post-authentication command injection vulnerability, CVE-2025-64328. This flaw allowed attackers, notably the INJ3CTOR3 group, to deploy the EncystPHP web shell, enabling remote command execution and persistent access. The majority of affected systems were located in the United States, with significant numbers also in Brazil, Canada, Germany, and France. The exploitation led to unauthorized outbound calls and potential lateral movement within networks.

This incident underscores the critical importance of promptly applying security patches and restricting administrative access to trusted networks. The widespread nature of these attacks highlights the ongoing threat to VoIP infrastructures and the necessity for organizations to implement robust security measures to protect against such vulnerabilities.

Why This Matters Now

The exploitation of CVE-2025-64328 in FreePBX systems by the INJ3CTOR3 group demonstrates the persistent threat to VoIP infrastructures. Organizations must urgently update their systems and enforce strict access controls to prevent unauthorized access and potential financial losses due to unauthorized call activities.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

CVE-2025-64328 is a post-authentication command injection vulnerability in FreePBX versions higher than 17.0.2.36, allowing authenticated users to execute arbitrary shell commands on the host system.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit the command injection vulnerability may have been constrained by enforcing strict identity-aware access controls.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing strict segmentation policies that restrict administrative access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement within the network would likely have been constrained by enforcing east-west traffic controls.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control communications may have been detected and constrained by enhanced visibility and control mechanisms.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts would likely have been constrained by enforcing strict egress policies.

Impact (Mitigations)

The overall impact of the attack could have been reduced by limiting the attacker's ability to exploit vulnerabilities and move laterally.

Impact at a Glance

Affected Business Functions

  • Telephony Services
  • VoIP Communications
  • Call Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of call records and user credentials.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access and limit lateral movement within the network.
  • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
  • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities indicative of web shell deployment.
  • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Ensure regular updates and patch management to address known vulnerabilities like CVE-2025-64328 promptly.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image