Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 24, 2026

CVE-2019-19006

High
EPSS 26.9%CISA KEV
Sangoma/FreePBX

Description

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

EPSS — Exploit Probability

26.9%

Higher than 96.3% of all CVEs

Required Action

https://wiki.freepbx.org/display/FOP/2019-11-20%2BRemote%2BAdmin%2BAuthentication%2BBypass ; https://nvd.nist.gov/vuln/detail/CVE-2019-19006

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
26.9%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Feb 3, 2026

Added to KEV

Feb 3, 2026

Remediation Due

Feb 24, 2026

Affected Product

Sangoma

FreePBX

View all Sangoma CVEs