โ† Back to Feed

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

CVE-2026-9586

September 2, 2026 ยท BleepingComputer ยท Severity: HIGH

This article reports active exploitation of CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. Attackers are actively exploiting the flaw, and organizations are urged to apply patches immediately and monitor for indicators of compromise. ๐Ÿ“Œ **Analyst Note:** This CVE is confirmed actively exploited in the wild. Apply patches immediately and monitor for indicators of compromise.

Key Takeaways

  • Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
  • The flaw allows remote attackers to execute arbitrary code without authentication, posing a critical risk to organizations using this VoIP system.
  • Organizations must apply patches immediately and monitor for indicators of compromise to prevent unauthorized access and potential data breaches.
โ˜• Buy a Coffee