CVE-2026-72578: FreePBX Framework
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.
Affected products
- FreePBX FreePBX Framework: version 17.0 only
Published 2026-08-10. Last modified 2026-08-28.