CVE Tools

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

BleepingComputerBy Bill Toulas

Reported exploitedSangoma Switchvox

Our summary

Security researchers at Horizon3 have confirmed active exploitation of CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that allows attackers to achieve remote code execution. The flaw exists within the /pa HTTP endpoint, where input from the PhoneIP field is directly concatenated into SQL queries without proper sanitization. Attackers are currently using this weakness to deploy reverse shells and exfiltrate process information from vulnerable systems. Sangoma addressed this issue along with eleven other vulnerabilities in release 8.4.0.2, so immediate upgrades are recommended for all exposed instances.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store