Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
What happened
A threat actor is actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and second-stage malware on internet-exposed instances. The flaw, patched in version 8.4.0.2, allows attackers to execute arbitrary SQL statements against the backend PostgreSQL database, with exploitation attempts observed since August 30.
Why it ranks #1
A threat actor is actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and second-stage malware on internet-exposed instances.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
What to do
Check internet-exposed Sangoma Switchvox instances for compromise indicators related to the actively exploited SQL injection flaw (CVE-2026-9586).
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- confirmed incident