ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-19006
Authentication Bypass in Sangoma FreePBX Admin Interface

Sangoma FreePBX contains an improper authentication flaw (CWE-287) that potentially allows unauthorized users to bypass password authentication on services provided by the FreePBX admin. An attacker triggers it by sending requests to the FreePBX admin interface without valid credentials, defeating the password check rather than exploiting a code-level bug. Successful exploitation grants unauthorized access to FreePBX administrative services, which can expose PBX configuration and allow management actions under another user's privileges. Any Sangoma FreePBX deployment is affected (CISA lists the affected product as Sangoma FreePBX with no version ranges specified), with risk concentrated on systems whose admin interface is reachable from the internet or untrusted networks. The flaw was added to CISA KEV on 2026-02-03, confirming known in-the-wild exploitation; EPSS estimates a 36.6% chance of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Apply mitigations per vendor instructions as required by CISA KEV, or discontinue use if mitigations are unavailable; federal agencies must follow BOD 22-01 guidance, including for cloud services. Because the flaw bypasses admin authentication, restrict the FreePBX admin interface to trusted networks (VPN or firewall allowlists) and avoid exposing it directly to the internet. Review FreePBX admin access logs for unexpected successful logins or unexplained configuration changes from unknown sources.

9.837% KEV PoC
  • Sangoma FreePBX Affected per CISA as 'Sangoma FreePBX'; no specific version ranges were provided in the available data
largetens of thousands of internet-exposed FreePBX admin panels (estimate)
CVE-2021-39935
Server-Side Request Forgery in GitLab Community and Enterprise Editions via CI Lint API

CVE-2021-39935 is a server-side request forgery (CWE-918) in GitLab Community Edition and Enterprise Edition that allows unauthorized external users to make the GitLab server issue requests through the CI Lint API. By abusing the server's network position, an attacker can reach internal-only resources such as loopback or private-network services, potentially mapping or accessing internal infrastructure without credentials. All deployments of the affected editions are potentially exposed, with actual risk depending on whether the CI Lint API is reachable by unauthenticated external users. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-03, indicating known exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed. EPSS estimates a 35.6% probability of exploitation within 30 days (98th percentile).

Do: Upgrade GitLab CE/EE to the patched release identified in GitLab's security advisory for CVE-2021-39935 (version numbers are not provided in the source data). Until patching is complete, restrict unauthenticated external access to the CI Lint API (e.g., at the reverse proxy or firewall) and review logs for unexpected requests to loopback or internal-network targets originating from CI lint calls. Federal agencies must follow BOD 22-01 remediation timelines following the 2026-02-03 KEV listing; discontinue or isolate use if mitigations are unavailable.

7.536% KEV
  • GitLab Community Edition (CE)
  • GitLab Enterprise Edition (EE)
largetens of thousands of internet-exposed self-managed GitLab instances; the affected code also runs on GitLab.com SaaS (millions of users)
CVE-2025-40551
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days.

Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application.

9.884% KEV
  • SolarWinds Web Help Desk
large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate
CVE-2025-64328
Post-Authentication OS Command Injection in Sangoma FreePBX Filestore Module

Sangoma FreePBX's filestore module within the Administrative interface (described alongside the Endpoint Manager module) contains an OS command injection flaw (CWE-78) in its testconnection -> check_ssh_connect() function, affecting versions 17.0.2.36 and above before 17.0.3. An attacker who is already authenticated — CVSS 4.0 scoring indicates high privileges are required — can trigger the test-connection function to inject and execute arbitrary operating-system commands. Successful exploitation gives the attacker remote access to the system as the 'asterisk' user, and in observed attacks this has been leveraged to deploy a weaponized web shell. Any FreePBX deployment running the affected module versions is exposed; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-03, and public reporting ties it to web shell campaigns that have compromised 900+ FreePBX instances. EPSS currently assigns an 84.6% probability of exploitation within 30 days (100th percentile), underscoring the urgency of patching.

Do: Upgrade the filestore/Endpoint Manager module to version 17.0.3 or later via FreePBX module administration, following vendor instructions — CISA KEV/BOD 22-01 requires applying vendor mitigations or discontinuing use if mitigation is unavailable. Hunt for the weaponized web shell described in Fortinet's referenced research, unexpected files or processes running as the asterisk user, and suspicious activity through the Administrative interface, and restrict admin access to trusted users and networks until patched.

8.685% KEV PoC
  • Sangoma FreePBX (filestore module, per CISA affected-product listing) Deployments running the vulnerable module version 17.0.2.36 or later, prior to 17.0.3
  • Sangoma FreePBX filestore module (Endpoint Manager) 17.0.2.36 and above, before 17.0.3; fixed in 17.0.3
moderate≥900 confirmed-compromised FreePBX instances; broader internet-exposed installed base unknown

Indicators of compromiseAll →

TypeIndicatorContext
domainhorizon3.aiomise of the affected server. The researcher Jimi Sebree of Horizon3.ai discovered the vulnerability. The second vulnerability adde
Full article495 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 03, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability
  • CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
  • CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
  • CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability 

The first vulnerability added to the catalog, tracked as CVE-2025-40551 (CVSS score of 9.8), is a deserialization of untrusted data that affects SolarWinds Web Help Desk. This vulnerability allows an unauthenticated attacker to achieve remote code execution, enabling the execution of arbitrary commands on the underlying host system and potentially leading to a complete compromise of the affected server. The researcher Jimi Sebree of Horizon3.ai discovered the vulnerability.

The second vulnerability added to the KeV catalog is a Server-Side Request Forgery (SSRF) issue, tracked as CVE-2021-39935 (CVSS score of 7.5). In March 2025, GreyNoise observed a significant rise in SSRF exploitation, with around 400 unique IPs actively targeting 10 SSRF vulnerabilities, including CVE-2021-39935. Many of these IPs were attempting to exploit multiple vulnerabilities simultaneously rather than targeting a single flaw. This pattern suggests an automation or pre-compromise reconnaissance, rather than typical botnet activity.

The third issue added to the catalog is CVE‑2019‑19006 (CVSS score of 9.8). The flaw is an improper authentication issue in Sangoma FreePBX that allows a remote attacker to bypass the login mechanism and gain full administrative access without valid credentials. This means an unauthenticated user can effectively take control of the PBX web interface, change configurations, access call logs, and manage users, all without needing to know any password.

The last issue added to the catalog, tracked as CVE‑2025‑64328 (CVSS score of 8.6), is an authenticated OS command injection vulnerability in the FreePBX Endpoint Manager. Once logged in, an attacker can inject arbitrary operating‑system commands through the testconnection function, which are then executed with the privileges of the asterisk user. This can lead to full server takeover, data theft, or use of the system as a pivot into the wider network.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA has ordered federal agencies to remediate all listed vulnerabilities, except the SolarWinds flaw, by February 24, 2026. The SolarWinds vulnerability must be addressed by the end of this week, February 6.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187592/security/u-s-cisa-adds-solarwinds-web-help-desk-sangoma-freepbx-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog.html