← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 2, 2026 · 07:08via The Hacker News

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Brief

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.

The vulnerability in question is CVE-2026-9586 (CVSS score: 9. 3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8. 3 (104997) that can allow attackers to remotely execute arbitrary code as

Read more on The Hacker News