Critical Switchvox Flaw Lets Attackers Deploy Reverse Shells Without Auth
A critical SQL injection flaw in Sangoma Switchvox allows unauthenticated remote code execution. Threat actors are actively exploiting CVE-2026-9586 to deploy reverse shells.
TL;DR
- Attackers are exploiting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox.
- The flaw allows remote code execution with no credentials required.
- Organizations using Switchvox SMB Edition 8.3 should patch immediately.
- Exploitation leads to reverse shell deployment and potential full system compromise.
- Threat actors are actively scanning and exploiting vulnerable instances.
Security researchers have identified active exploitation of a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform. The flaw, tracked as CVE-2026-9586, allows threat actors to execute arbitrary code remotely without authentication.
This severe security issue affects Switchvox SMB Edition 8.3 (104997) and has been assigned a CVSS score of 9.3, indicating critical severity. Organizations using this platform should take immediate action to mitigate potential compromise.
Vulnerability Details
- CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3
- The flaw has a CVSS score of 9.3, classified as critical severity
- No authentication is required to exploit this vulnerability
- Successful exploitation allows remote code execution as the web server user
- Attackers can deploy reverse shells and gain persistent access to affected systems
Impact and Mitigation
- Threat actors are actively scanning for and exploiting vulnerable Switchvox instances
- Successful attacks result in full system compromise without requiring credentials
- Organizations should immediately patch affected Switchvox installations
- Network segmentation and monitoring can help detect exploitation attempts
- Administrators should review logs for suspicious SQL queries or reverse shell activity
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.