Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

Attackers are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma's Switchvox VoIP platform, designated CVE-2026-9586, to achieve remote code execution and deploy reverse shells. Security researchers at Horizon3, who discovered the flaw, indicate that a significant number of internet-exposed Switchvox systems have likely already been targeted or are at imminent risk.
Switchvox is an enterprise VoIP management platform used for configuring and monitoring business phone systems. Horizon3 identified CVE-2026-9586 as the most critical among 12 vulnerabilities they reported to Sangoma on April 10. Sangoma subsequently released Switchvox version 8.4.0.2 on July 14, which includes fixes for all reported issues.
The vulnerability resides in the `/pa` HTTP endpoint of Sangoma Switchvox. This endpoint is exposed and processes XML messages containing specific key-value pairs. When `/pa` receives a request to notify another phone system, such as for an incoming or outgoing call event, it extracts the `PhoneIP` field from the XML message. The value of this field is then directly concatenated into an unparameterized SQL query, creating the SQL injection vulnerability.
Researchers demonstrated that a crafted XML request, sent via a `curl` command, can exploit this SQL injection remotely to execute operating-system commands. On August 30, Horizon3's honeypots detected active exploitation attempts on multiple systems in rapid succession. These attempts originated from a single source IP address, 176.65.148.184.
During these attacks, the threat actor executed an initial payload and then gathered information about the top processes running on the Switchvox system. This collected data was subsequently transmitted to a remote server in a base64-encoded format. The rapid succession of exploit attempts across multiple honeypots from the same IP address suggests widespread targeting of internet-exposed Switchvox instances.
Currently, approximately 4,000 Switchvox devices are accessible on the internet, with the majority located in the United States. While CVE-2026-9586 is being actively exploited, Horizon3 has not observed active exploitation of the other 11 flaws they previously discovered.
Given the ongoing exploitation, system administrators are strongly advised to upgrade to Switchvox version 8.4.0.2 or a later release as soon as possible. Additionally, administrators should check for signs of compromise, which may include suspicious entries in `/var/log/switchvox/db-quirks.log` and network connections to the attacker's observed IP address, particularly on port 39323.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.