Asterisk patches six DoS and security bypass flaws
Multiple vulnerabilities in Asterisk open-source PBX software allow remote denial of service, data integrity compromise, and security policy bypass across versions 20-23.
The French CERT has published an advisory detailing six security vulnerabilities affecting multiple versions of Asterisk, the widely-deployed open-source PBX platform. The flaws impact Asterisk versions 20.x through 23.x, as well as Certified Asterisk releases in the 20.x and 22.x branches. The vulnerabilities enable attackers to remotely trigger denial-of-service conditions, compromise data integrity, and bypass security policies implemented within the telephony system.
Asterisk has released patches addressing all six CVEs across the affected version ranges. Organizations running vulnerable versions should upgrade to Asterisk 20.20.1, 21.12.3, 22.10.1, or 23.4.1 depending on their deployment branch. Certified Asterisk users should apply version 20.7-cert11 or 22.8-cert3 as appropriate.
The vulnerabilities are tracked as CVE-2026-57184, CVE-2026-57186, CVE-2026-57187, CVE-2026-57194, CVE-2026-57200, and CVE-2026-57202. Full technical details are available through six corresponding GitHub security advisories published by the Asterisk project on June 25, 2026.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0805
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free