Threat actors are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection flaw in Sangoma Switchvox that can lead to remote code execution. Horizon3 and CISA have confirmed exploitation in the wild and added the issue to the KEV catalog alongside other recently abused vulnerabilities in Starlette, Kestra, and LiteLLM. #CVE-2026-9586 #SangomaSwitchvox #Horizon3 #CISA #Starlette #Kestra #LiteLLM
Keypoints
- CVE-2026-9586 is a critical flaw in Sangoma Switchvox.
- The bug is an unauthenticated SQL injection in an XML-processing endpoint.
- Attackers can use a single crafted request to run arbitrary SQL and gain remote code execution.
- Horizon3 reported active exploitation and shared indicators of compromise.
- CISA added CVE-2026-9586 and several other exploited flaws to its KEV catalog.
Read More: https://www.securityweek.com/sangoma-switchvox-vulnerabilities-exploited-in-the-wild/