A threat actor is actively exploiting the recently patched CVE-2026-9586 SQL injection flaw in internet-exposed Sangoma Switchvox instances, dropping reverse shells and later staging additional malware. Organizations using Switchvox should immediately check for compromise, review the listed indicators of compromise, and restrict access to the Switchvox interfaces and /pa endpoint if they cannot update. #CVE-2026-9586 #SangomaSwitchvox #Horizon3 #DefusedCyber #Asterisk
Keypoints
- CVE-2026-9586 affects Sangoma Switchvox SMB Edition 8.3 and enables unauthenticated SQL injection.
- The flaw was patched in Switchvox version 8.4.0.2 released on July 14, 2026.
- Exploitation attempts against vulnerable instances were first seen on August 30 from a single IP address.
- The attacker uses reverse shells, process enumeration, and second-stage malware deployment, possibly a cryptominer.
- Horizon3 advises checking for compromise and restricting access to Switchvox interfaces and the /pa endpoint.