Attackers exploit Issabel Framework flaw enabling unauthenticated OS command execution
A critical vulnerability CVE-2026-89026 (CVSS 9.8/9.3) has been found in the Issabel Framework, a web framework for an open-source PBX system. An unauthenticated remote attacker can execute arbitrary OS commands, and the vulnerability is already being actively exploited.
- CVE-2026-89026: CVSS v3.1 — 9.8, CVSS v4.0 — 9.3
- Allows OS command execution without authentication
- Vulnerability is already actively exploited in attacks
Read next
Security