HomeSecurityCritical Vulnerability Exposes Mitel MiCollab Platform to Hacking

Critical Vulnerability Exposes Mitel MiCollab Platform to Hacking

Mitel this week informed its customers about the availability of security patches for a critical vulnerability in MiCollab, which can be exploited remotely and without authentication.

See also: Hackers advertise new Nytheon AI tool on hacking forum

MiCollab vulnerability

The vulnerability, which does not currently appear to have a CVE identifier, is described as a path traversal affecting the NuPoint Unified Messaging (NPM) of MiCollab.

versions 9.8 SP2 (9.8.2.12) and earlier, while the vulnerability has been fixed in versions 9.8 SP3 (9.8.3.1) and later. MiCollab versions 10.0.0.26 and later are not affected.

Mitel MiCollab is a communication and collaboration platform that provides tools for voice communication, video calls, chats, web conferencing and team collaboration.

According to Mitel, this vulnerability could allow an attacker to gain unauthorized access to system configuration information, including non-sensitive user and network information, as well as perform unauthorized administrative actions on the MiCollab server.

See also: Vulnerabilities in photovoltaics expose electricity grids to hacking

Dahmani Toumi, the researcher credited with discovering the vulnerability, told SecurityWeek that the vulnerability can be exploited remotely over the internet on web-accessible MiCollab instances.

Critical Vulnerability Exposes Mitel MiCollab Platform to Hacking

Toumi said he found more than 20,000 such cases using the Shodan. It remains unclear how many of them are actually vulnerable to attacks.

According to the researcher, exploiting the vulnerability in real-world conditions could lead to data leakage, service outages, or further compromise of an organization's systems. He explained that Mitel released a patch for the vulnerability in February 2025. He also pointed out that this is essentially a bypass of the patch that was released for CVE-2024-41713, a similar vulnerability that was disclosed in the fall of 2024.

The US cybersecurity agency CISA had warned in early 2025 that CVE-2024-41713 had already been exploited in attacks, along with another MiCollab vulnerability, listed as CVE-2024-55550.

See also: Microsoft and CrowdStrike classify hacking group names

Based on the above, it is clear that Mitel's MiCollab is currently the target of increased interest from the cybersecurity, due to successive vulnerabilities that have been disclosed and exploited. The fact that CISA has already confirmed active exploitation of these vulnerabilities means that these are not theoretical risks but immediate threats with impacts in real environments. MiCollab administrators should check their versions and apply the latest patches immediately.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS