Sangoma develops a modestly represented but strategically prominent portfolio centered on FreePBX, Asterisk, and session border control products that serve telecommunications infrastructure and VoIP deployments worldwide. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the sensitivity of voice-communications platforms to both in-the-wild attack and proof-of-concept development. The exposure recurs across the Asterisk ecosystem and unified communications appliances through a durable set of input-handling and authentication weaknesses—cross-site scripting, SQL injection, OS command injection, path traversal, and improper authentication—that are characteristic of web-facing telephony management interfaces and protocol parsing layers. Defenders should treat updates to these core products as operationally critical given their role in call routing and session management; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sangoma over time
Signals from CVEs in this vendor scope (84 CVEs).
84 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64328HIGH FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrat | Nov 7, 2025 | 7.2 | 98 | YES | YES |
CVE-2025-57819CRITICAL FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenti | Aug 28, 2025 | 9.8 | 98 | YES | YES |
CVE-2019-19006CRITICAL Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. | Nov 21, 2019 | 9.8 | 84 | YES | NO |
CVE-2012-4869HIGH The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter | Sep 6, 2012 | 7.5 | 78 | NO | YES |
CVE-2014-1903HIGH admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions | Feb 18, 2014 | 7.5 | 67 | NO | YES |
CVE-2014-7235HIGH htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to | Oct 7, 2014 | 10.0 | 59 | NO | YES |
CVE-2025-66039CRITICAL FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "w | Dec 9, 2025 | 9.8 | 51 | NO | YES |
CVE-2023-49294HIGH Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cer | Dec 14, 2023 | 7.5 | 43 | NO | NO |
CVE-2026-46376CRITICAL FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial templ | May 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2021-45461CRITICAL FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the | Dec 22, 2021 | 9.8 | 36 | NO | NO |
Signals from CVEs in this vendor scope (84 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sangoma.
Media articles that mention a CVE ID that affects a product developed by Sangoma — matched by CVE ID, not by vendor name.