← Back to blog

Critical Switchvox Flaw Lets Attackers Deploy Reverse Shells Without Auth

A critical SQL injection flaw in Sangoma Switchvox allows unauthenticated remote code execution. Threat actors are actively exploiting CVE-2026-9586 to deploy reverse shells.

TL;DR

  • Attackers are exploiting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox.
  • The flaw allows remote code execution with no credentials required.
  • Organizations using Switchvox SMB Edition 8.3 should patch immediately.
  • Exploitation leads to reverse shell deployment and potential full system compromise.
  • Threat actors are actively scanning and exploiting vulnerable instances.

Security researchers have identified active exploitation of a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform. The flaw, tracked as CVE-2026-9586, allows threat actors to execute arbitrary code remotely without authentication.

This severe security issue affects Switchvox SMB Edition 8.3 (104997) and has been assigned a CVSS score of 9.3, indicating critical severity. Organizations using this platform should take immediate action to mitigate potential compromise.

Vulnerability Details

  • CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3
  • The flaw has a CVSS score of 9.3, classified as critical severity
  • No authentication is required to exploit this vulnerability
  • Successful exploitation allows remote code execution as the web server user
  • Attackers can deploy reverse shells and gain persistent access to affected systems

Impact and Mitigation

  • Threat actors are actively scanning for and exploiting vulnerable Switchvox instances
  • Successful attacks result in full system compromise without requiring credentials
  • Organizations should immediately patch affected Switchvox installations
  • Network segmentation and monitoring can help detect exploitation attempts
  • Administrators should review logs for suspicious SQL queries or reverse shell activity

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.