Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox that can lead to remote code execution. Horizon3 reported rapid attack attempts from a single source IP and warned that most internet-exposed Switchvox systems may already have been targeted. #CVE-2026-9586 #Switchvox #Sangoma #Horizon3

Keypoints

  • CVE-2026-9586 is an unauthenticated SQL injection in Sangoma Switchvox.
  • The flaw can be used to achieve remote code execution through the /pa endpoint.
  • Horizon3 observed active exploitation from the IP address 176.65.148.184.
  • Attackers attempted to establish a reverse shell and collect system process information.
  • Administrators should upgrade to Switchvox 8.4.0.2 or later and review logs for signs of compromise.

Read More: https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/