VYPR
researchPublished Sep 2, 2026· 1 source

Critical SQL Injection in Sangoma Switchvox Allows Unauthenticated RCE

Attackers are actively exploiting CVE-2026-9586, a critical SQL injection flaw in Sangoma Switchvox SMB Edition, enabling unauthenticated remote code execution.

Threat actors are actively exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability, identified as CVE-2026-9586, carries a CVSS score of 9.3, highlighting its critical severity. This unauthenticated SQL injection flaw resides in Sangoma Switchvox SMB Edition version 8.3 (build 104997).

The exploit allows attackers to remotely execute arbitrary code on affected systems without needing any prior authentication. This capability is particularly concerning given the nature of VoIP systems, which often handle sensitive business communications and can serve as pivot points into an organization's network. The ease of exploitation, due to the lack of authentication requirements, makes it an attractive target for malicious actors.

Initial reports indicate that attackers are leveraging this vulnerability to deploy reverse shells on compromised Switchvox servers. A reverse shell provides attackers with a command-line interface back to the victim's machine, allowing them to execute commands, exfiltrate data, or further compromise the network. The ability to establish such a connection without any credentials significantly lowers the barrier to entry for attackers.

Sangoma has acknowledged the vulnerability and is expected to release patches to address CVE-2026-9586. However, the active exploitation in the wild means that organizations using the affected Switchvox SMB Edition are at immediate risk. It is crucial for administrators to monitor their systems for any signs of compromise and to apply security updates as soon as they become available.

This incident underscores the ongoing threat posed by unauthenticated remote code execution vulnerabilities in widely used business communication infrastructure. VoIP systems, like other critical network appliances, are prime targets for attackers seeking to disrupt operations or gain unauthorized access to sensitive information. The SQL injection mechanism used in this exploit is a well-known attack vector, but its successful application in this context highlights potential gaps in the security testing and patching of such platforms.

Organizations using Sangoma Switchvox are strongly advised to consult Sangoma's official security advisories for the latest information on patches and mitigation strategies. Proactive security measures, including network segmentation and regular vulnerability scanning, can also help reduce the attack surface and limit the potential impact of such exploits. The active exploitation of CVE-2026-9586 serves as a stark reminder of the need for continuous vigilance in cybersecurity defenses.

Synthesized by Vypr AI