Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft 365 Suffers Widespread Outage with 502 and 503 Errors
September 16, 2026
VectraRAT Malware for Rent, Threatens Windows PCs
September 16, 2026
GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts
September 16, 2026
Home/CyberSecurity News/Critical Issabel PBX RCE actively exploited, patch immediately
CyberSecurity News

Critical Issabel PBX RCE actively exploited, patch immediately

Key Takeaways A critical remote code execution (RCE) vulnerability in the Issabel Framework, CVE-2026-89026, is under active exploitation. The flaw affects Issabel PBX deployments and allows...

Jennifer sherman
Jennifer sherman
September 16, 2026 3 Min Read
4 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability in the Issabel Framework, CVE-2026-89026, is under active exploitation.
  • The flaw affects Issabel PBX deployments and allows unauthenticated attackers to execute arbitrary OS commands.
  • The vulnerability stems from a hard-coded JSON Web Token (JWT) signing key, enabling token forgery.
  • A patch is available, and immediate remediation is critical for all internet-exposed Issabel PBX systems.

Issabel PBX Under Active Attack Due to Critical RCE Flaw

Cybersecurity researchers are urging immediate patching for Issabel PBX systems after discovering a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-89026, that is actively being exploited in the wild. The flaw in the Issabel Framework allows unauthenticated attackers to gain control of vulnerable PBX servers by forging authentication tokens.

Table Of Content

  • Key Takeaways
  • Issabel PBX Under Active Attack Due to Critical RCE Flaw
  • Technical Details of the Hard-Coded Key Flaw
  • Exploitation Path: From Forged Token to OS Command Execution
  • What You Should Do

Security firm VulnCheck has assigned the issue a severe CVSS v4 score of 9.3, classifying it as critical. The vulnerability impacts Issabel Framework versions predating commit b97dbaf0b71c1c36f841e672b664afbeb02773bd. The Shadowserver Foundation first detected exploitation activity for this vulnerability on September 9, 2026, highlighting the urgent need for organizations to secure their internet-facing Issabel PBX installations.

Technical Details of the Hard-Coded Key Flaw

The root cause of this critical vulnerability lies within the Issabel Framework’s pbxapi/index.php file, which contains a hard-coded HS256 JSON Web Token (JWT) signing key. This shared secret key across all affected installations fundamentally undermines the security model of JWTs, which are typically used to verify the authenticity and authorization of requests.

Because the same signing key is present in all unpatched Issabel deployments, an attacker can generate a bearer token that appears legitimate to a vulnerable Issabel server. This bypasses the need for valid Issabel accounts, passwords, or any prior access to the PBX environment, allowing attackers to submit forged tokens to exposed API endpoints.

The issue is categorized as CWE-321, “Use of Hard-coded Cryptographic Key.” Such vulnerabilities are particularly dangerous in widely deployed products, as the compromise of a single embedded key can expose every unpatched system to significant risk.

Exploitation Path: From Forged Token to OS Command Execution

With a successfully forged bearer token, an attacker can target the pbxapi/manager/originate endpoint. This endpoint interacts directly with the Asterisk Manager Interface (AMI), a crucial component of the PBX platform. Through this interaction, attackers can invoke the “System” application via the originate request, compelling Asterisk to execute arbitrary operating-system commands.

These commands are executed with the privileges of the Asterisk user account. Depending on the specific permissions granted to this service account and the overall server configuration, an attacker could potentially download malware, establish persistent access, exfiltrate sensitive data such as call records or PBX configuration, modify dial plans, misuse telephony resources, or pivot deeper into the victim’s internal network.

Given that the attack requires no authentication, no user interaction, and can be performed remotely, internet-exposed Issabel deployments are at the highest immediate risk.

What You Should Do

  • Patch Immediately: Update the Issabel Framework to a version that includes the security fix associated with commit b97dbaf0b771c1c36f841e672b664afbeb02773bd. Verify that the vulnerable shared JWT signing key is no longer present and that the patched code is active.
  • Restrict Network Access: Limit public internet exposure for PBX administration and API interfaces, especially the pbxapi endpoints and Asterisk management services.
  • Implement Secure Remote Access: For necessary remote administration, utilize VPN access, IP allowlists, strong multi-factor authentication, and network segmentation. VulnCheck has also added the vulnerability to its Known Exploited Vulnerabilities database, emphasizing the urgency of remediation.
  • Monitor for Suspicious Activity: Review web server, Issabel, Asterisk, and endpoint logs for any unusual bearer token activity, unexpected originate requests, execution of the “System” application, unrecognized shell commands, or outbound connections originating from the PBX server.
  • Incident Response: Any evidence of compromise should trigger an immediate incident response, including credential rotation, forensic analysis, and rebuilding affected systems as necessary.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical HPE RMC, OneView, and iLO 5 Flaws Let Attackers Remotely Execute Code

Next Post

Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed
September 16, 2026
Critical Issabel PBX RCE actively exploited, patch immediately
September 16, 2026
Critical HPE RMC, OneView, and iLO 5 Flaws Let Attackers Remotely Execute Code
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us