CVE Tools
Back to feed
Exploited in the wild Sangoma Switchvox rce Sangoma ics-ot-iot

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Help Net Security·By Zeljka Zorz··2 min read
CVE Tools coverage

Threat actors are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma Switchvox, identified as CVE-2026-9586. The flaw affects the SMB Edition 8.3 and allows attackers to execute arbitrary code against the underlying PostgreSQL database via a specific HTTP POST request. Honeypot data indicates that attacks began on August 30, with intruders deploying reverse shells and enumerating system processes.

Organizations should immediately verify whether they are running version 8.4.0.2, the patch released by Sangoma on July 14, 2026, which resolves this issue. If updating is not possible immediately, administrators should restrict network access to the affected "/pa" endpoint to mitigate risk.