---
schema: 1
kind: vulnerability
title: "CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090 — Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska)"
headline: "CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090 — Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska)"
summary: "CERT-PL — three pre-authentication admin-bypass CVEs in Slican PBX (CVE-2026-35087 / -35089 / -35090, all CVSS 4.0 9.3 except -35089 at 8.7). Slican telephony equipment is widely deployed in Polish government, public administration and healthcare and is also sold across Central and Eastern Europe. CVE-2026-35090's hardcoded caller-ID admin bypass on the PSTN modem interface is particularly notable — if remote management is disabled, the call temporarily re-enables it (CERT Polska, 2026-05-27; ENISA EUVD entry, 2026-05-27)."
discovered_at: "2026-05-28T05:00:07Z"
event_date: 2026-05-27
run_id: 2026-05-28-3e33200a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - auth-bypass
  - default-config
  - patch-available
  - enisa-critical
regions:
  - europe
sectors:
  - public-sector
  - healthcare
  - telco
entities: []
cves:
  - id: CVE-2026-35087
    cvss: "9.3"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
      - enisa-critical
  - id: CVE-2026-35089
    cvss: "8.7"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
      - enisa-critical
  - id: CVE-2026-35090
    cvss: "9.3"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
      - enisa-critical
sources:
  - url: "https://cert.pl/en/posts/2026/05/CVE-2026-35087/"
    publisher: CERT Polska
    role: primary
  - url: "https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-32276"
    publisher: ENISA EUVD-2026-32276
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Slican PBX — patch to IPx 6.61.0040 / CCT-1668 + MAC-6400 6.56.0430 / CXS-0424 6.30.0510 / NCP 1.24.0250.** Three unauthenticated admin-bypass CVEs (CVE-2026-35087 / -35089 / -35090). If you cannot patch immediately, restrict admin-protocol access by source IP at the upstream firewall and disable the PSTN modem management interface — CVE-2026-35090's caller-ID bypass temporarily re-enables remote management even when configured off. Reference: [CERT Polska](https://cert.pl/en/posts/2026/05/CVE-2026-35087/)."
migrated_from: briefs/2026-05-28.md
---

CERT Polska disclosed three vulnerabilities in Slican PBX firmware on 2026-05-27; Slican is a Polish manufacturer of PBX and IP-telephony equipment with broad deployment in Polish government, public administration and healthcare, and is also sold across Central and Eastern Europe ([CERT Polska, 2026-05-27](https://cert.pl/en/posts/2026/05/CVE-2026-35087/); [ENISA EUVD-2026-32276, 2026-05-27](https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-32276)). CVE-2026-35087 (CVSS 4.0: 9.3) — the administrative protocol accepts a specific command that bypasses credential checks, granting admin shell access. CVE-2026-35089 (CVSS 4.0: 8.7) — the secure key protecting the admin service is generated deterministically from system properties obtainable without authentication; an attacker can recompute the key and extract admin credentials. CVE-2026-35090 (CVSS 4.0: 9.3) — the remote management modem interface accepts a hardcoded caller-ID that bypasses admin authentication on the PSTN side; if remote access is disabled, the call temporarily re-enables it. All three are exploitable remotely without authentication. Affected/fixed pairs: IPx series (≥ 6.61.0040), CCT-1668 / MAC-6400 (≥ 6.56.0430), CXS-0424 (≥ 6.30.0510), NCP (≥ 1.24.0250). EOL hardware (versions ≤ 4.xx — CCT-1668 CCT1CPU, MAC-6400, CXS-0424 discontinued 2011/2012) will not receive patches; vendor recommends hardware replacement.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-48842 | Roundcube Webmail (`virtuser_query` plugin) | 8.1 | n/a | No | No (PoC reported) | 1.6.16 LTS / 1.7.1 | [Roundcube](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1) |
| CVE-2026-48843 | Roundcube Webmail (SVG `animate` CSS sanitiser) | High | n/a | No | No | 1.6.16 LTS / 1.7.1 | [Roundcube](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1) |
| CVE-2026-48844 | Roundcube Webmail (LDAP `autovalues`) | High | n/a | No | No | 1.6.16 LTS / 1.7.1 | [Roundcube](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1) |
| CVE-2026-48848 | Roundcube Webmail (HTML sanitiser SVG bypass) | High | n/a | No | No | 1.6.16 LTS / 1.7.1 | [Roundcube](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1) |
| CVE-2026-35087 | Slican PBX (IPx, CCT-1668, MAC-6400, CXS-0424, NCP) | 9.3 (4.0) | n/a | No | No | IPx 6.61.0040 / CCT-1668 + MAC-6400 6.56.0430 / CXS-0424 6.30.0510 / NCP 1.24.0250 | [CERT-PL](https://cert.pl/en/posts/2026/05/CVE-2026-35087/) |
| CVE-2026-35089 | Slican PBX (admin-service key derivation) | 8.7 (4.0) | n/a | No | No | Same as CVE-2026-35087 | [CERT-PL](https://cert.pl/en/posts/2026/05/CVE-2026-35087/) |
| CVE-2026-35090 | Slican PBX (PSTN modem caller-ID bypass) | 9.3 (4.0) | n/a | No | No | Same as CVE-2026-35087 | [CERT-PL](https://cert.pl/en/posts/2026/05/CVE-2026-35087/) |
| CVE-2026-48027 | Nx Console (VS Code extension) | Yes (CISA KEV) | Nx Console ≥ 18.100.0 | [Nx postmortem](https://nx.dev/blog/nx-console-v18-95-0-postmortem) |
| CVE-2026-45321 | TanStack Router (npm) | Yes (CISA KEV) | See [GHSA-g7cv-rxg3-hmpx](https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx) | [GHSA](https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx) |
| CVE-2026-8398 | DAEMON Tools Lite | Yes (CISA KEV) | DAEMON Tools Lite ≥ 12.6.0 | [Disc Soft](https://blog.daemon-tools.cc/post/security-incident) |
| CVE-2026-27771 | Gitea (`<` 1.26.2) | Gitea 1.26.2 | [NoScope](https://www.noscope.com/blog/gitea-instances-exposing-private-container) |
