Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Summary

Attackers are actively exploiting a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform, which allows for unauthenticated remote code execution. The flaw, identified as CVE-2026-9586, is a severe SQL injection vulnerability enabling attackers to deploy reverse shells without needing credentials.

IFF Assessment

FOE

This vulnerability allows unauthenticated remote code execution, which is a severe threat to defenders.

Severity

9.3 Critical

The CVSS score of 9.3 indicates a critical severity, reflecting the potential for unauthenticated attackers to remotely execute arbitrary code, which is highly impactful and exploitable.

Defender Context

This highlights the ongoing risk of unpatched VoIP systems being targeted by attackers. Defenders need to prioritize patching Switchvox deployments and segmenting VoIP networks to mitigate the impact of such vulnerabilities. Monitoring for indicators of compromise related to reverse shell deployment is crucial.

Read Full Story →