Sangoma Switchvox Vulnerabilities Exploited in the Wild
Summary
Multiple vulnerabilities in Sangoma's Switchvox phone system are being actively exploited in the wild. One notable flaw, CVE-2026-9586, is an unauthenticated SQL injection vulnerability that allows for remote code execution.
IFF Assessment
The active exploitation of vulnerabilities in a widely used communication system poses a significant risk to organizations, potentially leading to unauthorized access and compromise.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.
Defender Context
Organizations utilizing Sangoma Switchvox should prioritize patching these vulnerabilities immediately due to active exploitation. Defenders should monitor network traffic for signs of compromise related to SQL injection attempts and unauthorized code execution.