# Multiple privilege escalation vulnerabilities (CVE-2026-43284, CVE-2026-43500) affect…

Published: 2026-06-01 · Severity: high · Sectors: telecommunications
Canonical: https://vorant.io/reports/2eefba25-f303-48dd-bc8a-77961ab9a941/multiple-privilege-escalation-vulnerabilities-cve-2026-43284-cve-2026-43500

> Multiple privilege escalation vulnerabilities (CVE-2026-43284, CVE-2026-43500) affect numerous Mitel communication products across various versions requiring KB000127880 patch.

CERT-FR has published an advisory detailing multiple privilege escalation vulnerabilities affecting a broad range of Mitel unified communications and collaboration products. The vulnerabilities, tracked as CVE-2026-43284 and CVE-2026-43500, impact over 20 different Mitel product lines including MiCollab, MiVoice Business, OpenScape voice servers, and various telephony management systems. Affected versions span across multiple major releases, with many requiring the application of security patch KB000127880.

The vulnerabilities enable an attacker to elevate privileges on vulnerable systems, potentially allowing unauthorized administrative access to critical enterprise communication infrastructure. Products affected include cloud management portals, SIP-based telephony systems, border gateways, contact center platforms, and voice server solutions. Organizations using Mitel telecommunications infrastructure should prioritize patching efforts given the widespread nature of the affected product portfolio.

Mitel has released security advisory MISA-2026-0004 on May 28, 2026, providing remediation guidance and patches. Organizations should consult the vendor advisory to identify specific affected versions in their environment and obtain the appropriate security updates. The broad scope of affected products suggests this may represent a common code-base vulnerability impacting multiple Mitel product families.

## Mentioned in this report

- Vulnerabilities: CVE-2026-43284 (weaponized), CVE-2026-43500 (weaponized)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0672

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2eefba25-f303-48dd-bc8a-77961ab9a941/multiple-privilege-escalation-vulnerabilities-cve-2026-43284-cve-2026-43500.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
