CVE Tools

Sangoma Switchvox Vulnerabilities Exploited in the Wild

SecurityWeekBy Ionut Arghire

Reported exploitedSangoma SwitchvoxJFrog Artifactory

Our summary

Horizon3 has confirmed active exploitation of CVE-2026-9586, a critical-severity vulnerability in Sangoma Switchvox with a CVSS score of 9.3. This unauthenticated SQL injection flaw allows attackers to achieve remote code execution against the backend PostgreSQL database by sending crafted requests. In response to the ongoing attacks, CISA added this vulnerability to its Known Exploited Vulnerabilities catalog alongside five other issues affecting products such as JFrog Artifactory, SonicWall SMA1000, Starlette, Kestra, and LiteLLM. Federal agencies are directed to remediate the Switchvox flaw within three days, while patches for the associated Kestra and Starlette vulnerabilities must be applied within two weeks.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store