What happened
A denial-of-service vulnerability known as HTTP/2 Bomb (CVE‑2026‑49975) was published on 2 June. It affects the default HTTP/2 set-up of many popular web servers, including nginx, which 3CX uses. An attacker can use it to tie up a server's memory and make it unavailable, without logging in.
3CX released a security hotfix for Windows and Linux on 5 June, and published the full background on 8 June. Systems hosted by 3CX were updated centrally.
Are you affected?
- Self-managed, reachable from the internet (on your premises or in your own cloud): at risk. Apply the update now.
- Self-managed, behind a firewall or VPN: no emergency, but update in your next maintenance window.
- Hosted by 3CX: already fixed. Nothing to do.
How to update
In the 3CX admin console, go to System > Updates, select the latest update and install it.
- 20.0.9.987
- the version to install if you're on Update 9
- 20.0.8.1131
- the version to install on Update 8 or earlier
If you run weekly or monthly automatic updates, don't wait for the next scheduled run: update manually.
A security checklist for self-managed 3CX
- Keep automatic updates on, and run them daily rather than weekly or monthly.
- Make sure 3CX's emails reach you. 3CX sends security and licence notices to the email address linked to your system. Check they aren't being caught by spam filters.
- Expose as little as possible. Only open what your phones and apps need, and keep the admin console off the public internet where you can.
- Know who acts out of hours. Fixes like this one are often needed the same day.
- Keep a recent backup somewhere other than the phone system itself.
The bigger lesson
Phone systems are internet services now, and they need the same care as any other. Someone has to watch for alerts, judge the risk and apply fixes quickly, often out of hours.
That's what managed 3CX is for. If Infinitel manages your system, keeping it patched is part of the service. If you look after your own system and would rather not, talk to us.
Source: 3CX, “Security Update: HTTP/2 BOMB Vulnerability Mitigation”, 8 June 2026.
