• News/
  • bleepingcomputer-20260902210013

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

BleepingComputer
·
Bill Toulas
·
Published Sep 2, 2026
·
Updated

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. According to security researchers at Horizon3, most of the internet-exposed Switchvox systems have either already been targeted or will be soon. Switchvox is an enterprise VoIP management platform used to configure and monitor business phone systems. CVE-2026-9586 is the most serious of 12 flaws Horizon3 discovered and reported to Sangoma on April 10. The vendor fixed them in Switchvox version 8.4.0.2, released on July 14. The vulnerability is an unauthenticated SQL injection problem in Sangoma Switchvox’s /pa HTTP endpoint. The researchers explain that the endpoint is exposed and parses an XML message containing specific key-value pairs. When /pa receives a request to notify another phone system, such as for an incoming or outgoing call event, it extracts the PhoneIP field from the XML message and directly concatenates its value into an unparameterized SQL query. The researchers demonstrated that this SQL injection can be exploited remotely to execute operating-system commands through a crafted XML request sent using the curl command. On August 30, Horizon3’s honeypots observed active exploitation on multiple systems in rapid succession from a single source IP address (176.65.148.184), with the attacker attempting to establish a reverse shell. In these attempts, the attacker executed an initial payload...

Read full article

Affected Software

1 affected component
Sangoma Switchvox VoIP platform<8.4.0.2

Frequently Asked Questions

1

Which Switchvox versions address the exploited vulnerability?

Sangoma fixed CVE-2026-9586, along with the other reported flaws, in Switchvox version 8.4.0.2, released on July 14.

2

How does CVE-2026-9586 enable remote code execution?

The unauthenticated /pa HTTP endpoint processes XML notifications and inserts the PhoneIP field directly into an unparameterized SQL query. A crafted XML request can exploit this SQL injection to execute operating-system commands remotely.

3

What systems are at risk?

Internet-exposed Sangoma Switchvox systems are at risk. Horizon3 researchers said most exposed systems have already been targeted or will be targeted soon.

4

Is exploitation of this flaw confirmed?

Yes. The article states that attackers are actively exploiting CVE-2026-9586 to deploy reverse shells, and the flaw was KEV-listed on September 2, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203