Search
Find merged stories by title or summary.
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .
Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks
A critical vulnerability in Sangoma Switchvox is being actively exploited , affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics. The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on vulnerable systems without needing valid credentials. Horizon3.ai researchers observed valid exploitation attempts against internet-exposed Switchvox devices on August 30, 2026, with attackers attempting to deploy reverse shells for remote command-line access to compromised VoIP servers . CVE-2026-9586 is an unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition 8. 3, build 104997, and earlier releases. The issue has a CVSS severity score of 9. 3 and can lead to remote code execution.
Hackers Exploit Critical Sangoma Switchvox SQL Injection Flaw for Unauthenticated RCE
Threat actors are actively attempting to exploit CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that can be escalated to remote code execution. Researchers at Horizon3.ai said internet-facing honeypots run alongside Defused Cyber captured valid exploitation attempts on August 30, several weeks after Sangoma released security fixes for the enterprise VoIP platform. Sangoma Switchvox is an on-premises telephony management solution used by organizations to configure business phone systems, voicemail, call forwarding, device provisioning, call monitoring, and analytics. Critical Sangoma Switchvox SQL Injection Flaw The vulnerability affects an unauthenticated HTTP endpoint, /pa , which is designed to handle phone notification events for supported devices. According to Horizon3. ai , the issue exists in the Perl-based PhoneAppsHandler.
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [... ]
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on the open-source Asterisk engine and aimed at small and medium-size businesses. It can be deployed on-premises, in the cloud, or on virtualized infrastructure. CVE-2026-9586, found in Sangoma Switchvox SMB Edition 8. 3, allows attackers to … More → The post Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) appeared first on Help Net Security .
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9. 3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8. 3 (104997) that can allow attackers to remotely execute arbitrary code as
CVE-2026-9586 - Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
You've reached the end of current stories for this search.
