Critical Vulnerabilities in Sangoma Switchvox Exploited for Remote Code Execution

Critical Vulnerabilities in Sangoma Switchvox Exploited for Remote Code Execution

First seen 2 Sep 2026, 08:15 UTC Thehackernewslabs.sra.iowww.cve.org 78.0

Article Content

Browse articles
ThreatCluster

Sangoma Switchvox SMB Edition 8.3 (104997) has multiple vulnerabilities, including CVE-2026-9586, a critical unauthenticated SQL injection flaw allowing remote code execution. This vulnerability enables attackers to execute arbitrary SQL statements and gain superuser access to the PostgreSQL database without credentials. Exploitation attempts began on August 30, 2026, with approximately 4,000 instances exposed on the internet, primarily in the U.S. Security Risk Advisors (SRA) Labs reported successful exploitation, including the deployment of reverse shells and exfiltration of sensitive data. Sangoma released patches for these vulnerabilities in version 8.4.0.2 on July 14, 2026. Other vulnerabilities identified include CVE-2026-9585 (reflected XSS), CVE-2026-9587 (LFI), and CVE-2026-9588 (stored XSS). Organizations using affected versions are urged to apply the patches immediately to mitigate risks.

Key Points: • CVE-2026-9586 allows unauthenticated remote code execution via SQL injection. • Approximately 4,000 Switchvox instances are exposed to the internet, mainly in the U.S. • Sangoma released patches on July 14, 2026, but exploitation attempts began on August 30.

Timeline

2026-07-14
Patches released for vulnerabilities
Sangoma released version 8.4.0.2 to address the vulnerabilities in Switchvox SMB Edition.
Thehackernews
2026-07-17
CVE-2026-9585 and CVE-2026-9586 published
Sangoma disclosed multiple vulnerabilities in Switchvox SMB Edition 8.3, including critical SQL injection and XSS flaws.
labs.sra.io
2026-08-30
Active exploitation observed
Exploitation attempts against CVE-2026-9586 began, targeting exposed Switchvox instances.
Thehackernews