Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Reported exploitedSwitchvox SMB EditionOur summary
Attackers are actively exploiting a critical unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, in Sangoma Switchvox SMB Edition 8.3 (104997). This flaw, which carries a CVSS score of 9.3, permits remote code execution as the PostgreSQL superuser without requiring any credentials by manipulating data through the /pa endpoint. Sangoma released a patch for this issue in version 8.4.0.2 on July 14, 2026, but recent reports indicate that exploitation attempts began appearing in the wild starting August 30, 2026. Security researchers have observed attackers deploying reverse shells and attempting to exfiltrate sensitive keys from roughly 4,000 exposed instances, many of which remain vulnerable.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.