Sangoma Switchvox Vulnerabilities Exploited in the Wild

Summary

Multiple vulnerabilities in Sangoma's Switchvox phone system are being actively exploited in the wild. One notable flaw, CVE-2026-9586, is an unauthenticated SQL injection vulnerability that allows for remote code execution.

IFF Assessment

FOE

The active exploitation of vulnerabilities in a widely used communication system poses a significant risk to organizations, potentially leading to unauthorized access and compromise.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.

Defender Context

Organizations utilizing Sangoma Switchvox should prioritize patching these vulnerabilities immediately due to active exploitation. Defenders should monitor network traffic for signs of compromise related to SQL injection attempts and unauthorized code execution.

Read Full Story →