CVE Tools

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

The Hacker NewsBy The Hacker News

Reported exploitedSwitchvox SMB Edition

Our summary

Attackers are actively exploiting a critical unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, in Sangoma Switchvox SMB Edition 8.3 (104997). This flaw, which carries a CVSS score of 9.3, permits remote code execution as the PostgreSQL superuser without requiring any credentials by manipulating data through the /pa endpoint. Sangoma released a patch for this issue in version 8.4.0.2 on July 14, 2026, but recent reports indicate that exploitation attempts began appearing in the wild starting August 30, 2026. Security researchers have observed attackers deploying reverse shells and attempting to exfiltrate sensitive keys from roughly 4,000 exposed instances, many of which remain vulnerable.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store