Experts warn of actively exploited FreePBX zeroSecurity Affairs·Aug 29, 13:20 UTC · Aug 29, 2025Exploit / PoC in the wildCVE-2025-5781960
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell AttacksThe Hacker News·Mar 4, 16:55 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2025-6432860
U.S. CISA adds SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 3, 21:06 UTC · Feb 3, 2026Exploit / PoC in the wildCVE-2019-19006CVE-2021-39935CVE-2025-40551+1 CVEs60
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60