LIVE · cybersecurity feed
Live wire
CVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud Emails
CVE-2026-89026critical

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

zeroday.news ·

Attackers are actively exploiting a critical vulnerability in the Issabel Framework, a web-based component of the open-source unified communications PBX software. This flaw, identified as CVE-2026-89026, allows for unauthenticated remote operating system (OS) command execution, posing a significant risk to affected systems.

The vulnerability stems from a hard-coded credential within the Issabel Framework. This hard-coded credential can be leveraged by an unauthenticated remote attacker to bypass authentication mechanisms and execute arbitrary OS commands on the underlying system. The CVSS v3.1 score for this vulnerability is 9.8, while the CVSS v4.0 score is 9.3, both indicating a critical severity level.

The Issabel Framework is integral to the Issabel PBX software, which is widely used for managing voice, fax, chat, and other unified communications services. Exploitation of this flaw could grant attackers full control over the PBX system, potentially leading to eavesdropping on calls, manipulating call routing, or using the system as a pivot point for further network intrusion.

This class of vulnerability, involving hard-coded credentials, is particularly dangerous because it provides a static, unchangeable entry point for attackers. Unlike other authentication bypasses that might require specific conditions or user interaction, a hard-coded credential can be exploited directly once discovered, often without any prior authentication.

Mitigation for such vulnerabilities typically involves patching the affected software immediately upon availability from the vendor. In cases where a patch is not yet available, organizations might consider implementing network-level access restrictions to the Issabel Framework interface, such as limiting access to trusted IP addresses or internal networks only. Monitoring for unusual activity originating from or directed at the Issabel system is also crucial.

The active exploitation of this flaw underscores the persistent threat posed by critical vulnerabilities in widely deployed software, particularly those managing sensitive communication infrastructure. It highlights the importance of robust security practices, including regular security audits, prompt patching, and adherence to secure coding principles to avoid the introduction of hard-coded secrets.

vulnerabilities in this storyCVE-2026-89026
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

CVE-2026-58704high

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

vulnerability

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero h

ai

BragJack Attack Can Turn a Browser's Agentic AI Against It

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

ai

Self-improving AI should slow down, von der Leyen tells EU lawmakers

European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State of the Union address to the European Parliament in Strasbourg, she also committed the EU to joint work with Canada, the U.K. and other partners on evaluating and verifying

nation-state

Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.