Exploited in the wild Sangoma Switchvox rce Sangoma ics-ot-iot
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
CVE Tools coverage
Threat actors are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma Switchvox, identified as CVE-2026-9586. The flaw affects the SMB Edition 8.3 and allows attackers to execute arbitrary code against the underlying PostgreSQL database via a specific HTTP POST request. Honeypot data indicates that attacks began on August 30, with intruders deploying reverse shells and enumerating system processes.
Organizations should immediately verify whether they are running version 8.4.0.2, the patch released by Sangoma on July 14, 2026, which resolves this issue. If updating is not possible immediately, administrators should restrict network access to the affected "/pa" endpoint to mitigate risk.