VulnerabilityBleeping Computer
9.8 — CRITICAL
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Attackers are exploiting CVE-2026-9586, a critical SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells on targeted systems. Most internet-exposed Switchvox instances have already been targeted or will be soon.
⚙️Technical Details
CVEs
CVE-2026-9586
Affected Systems
Sangoma Switchvox SMB Edition 8.3 (104997)
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
System administrators of internet-exposed Sangoma Switchvox systems
🛡️Recommended Actions
1Upgrade to Switchvox version 8.4.0.2 or later as soon as possible
2Monitor /var/log/switchvox/db-quirks.log for suspicious statements
3Check network connections for signs of compromise, particularly on port 39323
📦Affected Products
Sangoma Switchvox
🔐NVD Verified DataVERIFIED
CVE-2026-9586 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-89
Affected Products (CPE)
Sangoma Switchvox
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
