Critical Exploitation of Sangoma Switchvox Vulnerabilities Underway
Article Content
Sangoma Switchvox SMB Edition 8.3 is facing active exploitation of multiple vulnerabilities, particularly CVE-2026-9586, which allows unauthenticated SQL injection leading to remote code execution. The flaw can be exploited by sending crafted HTTP POST requests to the /pa endpoint, enabling attackers to execute arbitrary SQL statements against the PostgreSQL database. Approximately 4,000 internet-exposed instances are at risk, primarily in the U.S. The vulnerabilities were discovered by Horizon3 and Security Risk Advisors, with patches released on July 14, 2026. Exploitation attempts began on August 30, 2026, with attackers deploying reverse shells on compromised systems. Organizations are urged to check for signs of compromise and restrict access to vulnerable interfaces. The CVSS score for CVE-2026-9586 is rated at 9.3, indicating a critical severity level.
Key Points: • CVE-2026-9586 allows unauthenticated remote code execution via SQL injection. • Approximately 4,000 vulnerable Switchvox instances are exposed on the internet. • Active exploitation attempts have been confirmed since August 30, 2026.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.