LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
CVE-2026-9586

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

zeroday.news ·

Attackers are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma's Switchvox VoIP platform, designated CVE-2026-9586, to achieve remote code execution and deploy reverse shells. Security researchers at Horizon3, who discovered the flaw, indicate that a significant number of internet-exposed Switchvox systems have likely already been targeted or are at imminent risk.

Switchvox is an enterprise VoIP management platform used for configuring and monitoring business phone systems. Horizon3 identified CVE-2026-9586 as the most critical among 12 vulnerabilities they reported to Sangoma on April 10. Sangoma subsequently released Switchvox version 8.4.0.2 on July 14, which includes fixes for all reported issues.

The vulnerability resides in the `/pa` HTTP endpoint of Sangoma Switchvox. This endpoint is exposed and processes XML messages containing specific key-value pairs. When `/pa` receives a request to notify another phone system, such as for an incoming or outgoing call event, it extracts the `PhoneIP` field from the XML message. The value of this field is then directly concatenated into an unparameterized SQL query, creating the SQL injection vulnerability.

Researchers demonstrated that a crafted XML request, sent via a `curl` command, can exploit this SQL injection remotely to execute operating-system commands. On August 30, Horizon3's honeypots detected active exploitation attempts on multiple systems in rapid succession. These attempts originated from a single source IP address, 176.65.148.184.

During these attacks, the threat actor executed an initial payload and then gathered information about the top processes running on the Switchvox system. This collected data was subsequently transmitted to a remote server in a base64-encoded format. The rapid succession of exploit attempts across multiple honeypots from the same IP address suggests widespread targeting of internet-exposed Switchvox instances.

Currently, approximately 4,000 Switchvox devices are accessible on the internet, with the majority located in the United States. While CVE-2026-9586 is being actively exploited, Horizon3 has not observed active exploitation of the other 11 flaws they previously discovered.

Given the ongoing exploitation, system administrators are strongly advised to upgrade to Switchvox version 8.4.0.2 or a later release as soon as possible. Additionally, administrators should check for signs of compromise, which may include suspicious entries in `/var/log/switchvox/db-quirks.log` and network connections to the attacker's observed IP address, particularly on port 39323.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

ai

Smashing Security podcast #483: This AI helps thieves steal your iPhone

You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees

cloud

Summer 2024 weather report: Cloudflare with a chance of Intern-ets

This summer, Cloudflare welcomed approximately 60 interns from all around the globe, on a mission to #HelpBuildABetterInternet. Join us as we dive into what we accomplished and our experiences!

ai

Claude Mythos only model to complete full cyber kill chain, experts say

Cyber Weapon Index finds AI attacks 'imminent'