Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox that can lead to remote code execution. Horizon3 reported rapid attack attempts from a single source IP and warned that most internet-exposed Switchvox systems may already have been targeted. #CVE-2026-9586 #Switchvox #Sangoma #Horizon3
Keypoints
- CVE-2026-9586 is an unauthenticated SQL injection in Sangoma Switchvox.
- The flaw can be used to achieve remote code execution through the /pa endpoint.
- Horizon3 observed active exploitation from the IP address 176.65.148.184.
- Attackers attempted to establish a reverse shell and collect system process information.
- Administrators should upgrade to Switchvox 8.4.0.2 or later and review logs for signs of compromise.