Critical Exploitation of Sangoma Switchvox Vulnerabilities Underway

Critical Exploitation of Sangoma Switchvox Vulnerabilities Underway

First seen 2 Sep 2026, 08:15 UTC Thehackernewslabs.sra.ioHelpnetsecurityScworldBleepingcomputer+4 78.8

Article Content

Browse articles
ThreatCluster

Sangoma Switchvox SMB Edition 8.3 is facing active exploitation of multiple vulnerabilities, particularly CVE-2026-9586, which allows unauthenticated SQL injection leading to remote code execution. The flaw can be exploited by sending crafted HTTP POST requests to the /pa endpoint, enabling attackers to execute arbitrary SQL statements against the PostgreSQL database. Approximately 4,000 internet-exposed instances are at risk, primarily in the U.S. The vulnerabilities were discovered by Horizon3 and Security Risk Advisors, with patches released on July 14, 2026. Exploitation attempts began on August 30, 2026, with attackers deploying reverse shells on compromised systems. Organizations are urged to check for signs of compromise and restrict access to vulnerable interfaces. The CVSS score for CVE-2026-9586 is rated at 9.3, indicating a critical severity level.

Key Points: • CVE-2026-9586 allows unauthenticated remote code execution via SQL injection. • Approximately 4,000 vulnerable Switchvox instances are exposed on the internet. • Active exploitation attempts have been confirmed since August 30, 2026.

Ask AI about this cluster

Timeline

2026-07-14
Patches released for vulnerabilities
Sangoma released version 8.4.0.2 to address multiple vulnerabilities in Switchvox SMB Edition 8.3.
Helpnetsecurity
2026-07-17
CVE-2026-9586 published
The critical SQL injection vulnerability in Switchvox was officially published, detailing its impact.
labs.sra.io
2026-07-17
CVE-2026-9585 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CVE-2026-9587 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CVE-2026-9588 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
Active exploitation observed
Threat actors began exploiting CVE-2026-9586, deploying reverse shells on vulnerable systems.
Thehackernews