Vulnerability Research

Published findings from Evaluris security research, with full references to the official CVE records.

CVE-2026-63722·VulnCheck·

ICEcoder Unauthenticated Remote Code Execution

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution.

High 8.7ICEcoderCWE-306

Researchers: Adrian Gaitan, Saidakbarxon Maxsudxonov, Reju

CVE-2026-72578·Turan Security·

FreePBX Framework Cross-Site Request Forgery

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.

High 8.8FreePBX FrameworkCWE-352

Researchers: Adrian Gaitan