CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7524

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

CVE-2026-89026, a critical flaw in Issabel Framework affecting unified communications PBX software, allows unauthenticated remote attackers to execute arbitrary OS commands via a hard-coded credential vulnerability. The flaw carries a CVSS v4.0 score of 9.3 and is under active exploitation in the wild.

Why it matters: Organizations running Issabel Framework-based communications systems face immediate risk of full system compromise; patching or disabling unauthenticated access should be prioritized today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary