Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: pbx (1 article)Clear

Exploited Issabel PBX flaw uses a shared hardcoded key to run commands unauthenticated

Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.

Check
Update Issabel Framework to the patched version that replaces the shared signing key, and take the phone system's web interface off the public internet, restricting it to trusted management networks.
Affected
Organizations running internet-exposed Issabel Framework phone systems (CVE-2026-89026); because the signing key is identical everywhere, an unauthenticated attacker can forge a token and run operating-system commands, and exploitation is underway.
Fix
Patch to remove the hardcoded key, restrict and monitor access to the PBX web and management interfaces, hunt for forged-token requests and unexpected command execution, and rotate credentials if compromise is suspected.