Freeswitch is an open-source telecommunications platform and soft-switch engine widely deployed in VoIP infrastructure, carrier networks, and unified communications systems, presenting a strategically important but narrowly scoped attack surface. Vulnerabilities affecting the platform skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety and authentication-handling weakness classes including improper authentication, input-validation failures, out-of-bounds writes, heap-based buffer overflows, and buffer-boundary violations that are characteristic of a large native codebase handling untrusted protocol data. The exposure concentrates entirely within the core Freeswitch product itself, making patch adoption and deployment segmentation critical for operators relying on this platform. Defenders should monitor this vendor's releases closely and treat critical advisories as high-priority in call-processing tiers; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeswitch over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19492CRITICAL FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. | Dec 2, 2019 | 9.8 | 58 | NO | YES |
CVE-2026-49841CRITICAL FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-49840CRITICAL FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-49847HIGH FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-49842HIGH FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-49475HIGH FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-45771HIGH FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-49843MEDIUM FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Jun 9, 2026 | 5.3 | 26 | NO | NO |
CVE-2021-37624HIGH FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Oct 25, 2021 | 7.5 | 26 | NO | NO |
CVE-2021-41145HIGH FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar | Oct 25, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeswitch.
Media articles that mention a CVE ID that affects a product developed by Freeswitch — matched by CVE ID, not by vendor name.