CVE-2026-73665
FreePBX UCP Node Arbitrary Command Execution Vulnerability
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A critical vulnerability exists in FreePBX's User Control Panel (UCP) Node server, allowing unauthenticated attackers to execute arbitrary commands. This is possible by connecting to custom namespaces that bypass authentication and sending crafted data, potentially compromising system integrity and availability.