← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 16, 2026 · 15:50via The Hacker News

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Brief

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.

The vulnerability in question is CVE-2026-89026 (CVSS v3. 1 score: 9. 8/CVSS v4. 0 score: 9. 3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

Read more on The Hacker News→