CVE WATCH / VULNERABILITY DETAIL

CVE-2026-54710

UNKNOWNCVSS 0NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privilege

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-54710 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-54710

UNKNOWNCVSS 0NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privilege

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]