Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Summary
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform. This vulnerability can be leveraged to achieve remote code execution on compromised systems.
IFF Assessment
The article details an actively exploited vulnerability that allows attackers to gain remote code execution, posing a direct threat to system security.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Sangoma Switchvox presents a significant risk for organizations using the platform, as attackers can gain remote code execution without authentication. Defenders should prioritize patching or implementing mitigating controls for CVE-2026-9586 to prevent unauthorized access and further compromise.