LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 3, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 24, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-19006 to its Known Exploited Vulnerabilities catalog on Feb 3, 2026, with a federal patch deadline of Feb 24, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin. This matters because administrative access to a PBX system can expose call routing, user accounts, and connected telephony resources.

How it works

The weakness is classified under CWE-287, improper authentication. An attacker can abuse the flaw to reach administrative services without supplying valid credentials that the application would normally require.

Am I affected? How to find it in your systems

Sangoma FreePBX typically runs on Linux-based servers that provide VoIP and PBX functions. Inventory instances by locating FreePBX installations through package managers, web server configurations, or network scans for known administrative interfaces. Check the exact versions and configurations deployed in your environment against the vendor advisory, as only the advisory lists the affected releases.

How to remediate

Apply the vendor update referenced in the advisory as the primary step. After patching, review authentication settings for the administrative interface and enforce any additional controls recommended for this class of weakness, such as restricting direct network access to management ports.

If you can't patch immediately

Apply mitigations per the vendor instructions. For cloud-hosted instances, follow applicable BOD 22-01 guidance. Where mitigations are unavailable, discontinue use of the affected product. Additional compensating steps include network segmentation that limits administrative interface exposure and monitoring for unexpected access patterns until the update can be applied.

If your data may have been exposed

Vulnerabilities that permit unauthorized administrative access can lead to data exposure when exploited. You can run a free exposure scan of your email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSangoma · FreePBX
WeaknessCWE-287
Added to CISA KEVFeb 3, 2026
Federal patch deadlineFeb 24, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities