CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability
Summary
Sangoma Switchvox has a SQL injection vulnerability allowing unauthenticated remote attackers to execute arbitrary SQL statements and potentially gain remote code execution. Stakeholders are instructed to apply vendor mitigations and comply with CISA's guidance on prioritizing security updates.
IFF Assessment
This vulnerability allows for remote code execution, posing a significant threat to systems and data.
Severity
The vulnerability allows for unauthenticated remote code execution, which has a high attack vector and critical impact on confidentiality, integrity, and availability.
CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.
Defender Context
This SQL injection vulnerability in Sangoma Switchvox presents a critical risk, enabling remote code execution by unauthenticated attackers. Defenders must prioritize applying vendor-provided mitigations and adhere to CISA's directives for timely patching of critical vulnerabilities to prevent exploitation.