CVE Tools
Back to feed
Exploited in the wild Sangoma Switchvox rce Sangoma ics-ot-iot

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Security researchers at Horizon3 have confirmed active exploitation of CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that allows attackers to achieve remote code execution. The flaw exists within the /pa HTTP endpoint, where input from the PhoneIP field is directly concatenated into SQL queries without proper sanitization. Attackers are currently using this weakness to deploy reverse shells and exfiltrate process information from vulnerable systems. Sangoma addressed this issue along with eleven other vulnerabilities in release 8.4.0.2, so immediate upgrades are recommended for all exposed instances.