CVE Tools

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Help Net SecurityBy Zeljka Zorz

Reported exploitedSangoma Switchvox

Our summary

Threat actors are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma Switchvox, identified as CVE-2026-9586. The flaw affects the SMB Edition 8.3 and allows attackers to execute arbitrary code against the underlying PostgreSQL database via a specific HTTP POST request. Honeypot data indicates that attacks began on August 30, with intruders deploying reverse shells and enumerating system processes.

Organizations should immediately verify whether they are running version 8.4.0.2, the patch released by Sangoma on July 14, 2026, which resolves this issue. If updating is not possible immediately, administrators should restrict network access to the affected "/pa" endpoint to mitigate risk.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store