Critical Sangoma Switchvox vulnerability actively exploited in wild

CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP systems, was actively exploited in the wild by 3 September 2026. Security researchers at Defused Cyber and Horizon3 documented reverse-shell deployments affecting approximately 4,000 internet-exposed systems.

11 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Honeypot data confirms active exploitation of Sangoma Switchvox RCE vulnerability CVE-2026-9586, affecting ~4,000 internet-exposed systems. Defused Cyber recorded reverse shells and https:// deafnews.

mastodon:infosec-exchangeother28d ago kagi ↗

Honeypot data confirms active exploitation of Sangoma Switchvox RCE vulnerability CVE-2026-9586, affecting ~4,000 internet-exposed systems. Defused Cyber recorded reverse shells and https:// deafnews.it/en/article/honeypo t-confirms-active-exploitation-of-sangoma-switchvox-rce

CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution. # Sangoma # Switchvox # CVE20269586 # RCE

mastodon:infosec-exchangeother28d ago kagi ↗

CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution. # Sangoma # Switchvox # CVE20269586 # RCE # SQLInjection # VoIP # InfoSec # ExploitedInTheWild https:// securityonline.info/sangoma-sw itchvox-cve-2026-9586-rce/?utm_source=mastodon&utm_medium=jetpack_social

🤖 CVE-2026-9586 (CVSS 9.3): critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition 8.3, exploited in the wild to deploy reverse shells without credentials. Enterprise VoIP admins sho

mastodon:infosec-exchangeother27d ago kagi ↗

🤖 CVE-2026-9586 (CVSS 9.3): critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition 8.3, exploited in the wild to deploy reverse shells without credentials. Enterprise VoIP admins should patch. 🔗 https:// thehackernews.com/2026/09/atta ckers-exploit-critical-switchvox.html # CVE # Exploit # RCE # VoIPSec # CyberSec

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on Postgre

mastodon:infosec-exchangeother27d ago kagi ↗

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. # Switchvox # SqlInjection # ThreatIntel https:// cyberworldops.eu/en/switchvox- under-at

🔴 EXPLOITED Sangoma Switchvox has a critical unauthenticated flaw (CVE-2026-9586, CVSS 9.3) that lets a stranger run code on the phone system. Patched in July, mass-exploited since Aug 30. Around 4,0

mastodon:infosec-exchangeother27d ago kagi ↗

🔴 EXPLOITED Sangoma Switchvox has a critical unauthenticated flaw (CVE-2026-9586, CVSS 9.3) that lets a stranger run code on the phone system. Patched in July, mass-exploited since Aug 30. Around 4,000 consoles are exposed. Fix: update to 8.4.0.2 and hunt the logs. https:// suriq.io/blog/switchvox-cve-20 26-9586-unauth-rce-exploited # CVE # infosec # cybersecurity

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. https://www. bleepingcomp

mastodon:infosec-exchangeother27d ago kagi ↗

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. https://www. bleepingcomputer.com/news/secu rity/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/

🤖 CVE-2026-9586: unauthenticated SQL injection in Sangoma Switchvox (VoIP PBX) actively exploited in the wild, leading to remote code execution. Attackers deploy reverse shells on exposed instances.

mastodon:infosec-exchangeother27d ago kagi ↗

🤖 CVE-2026-9586: unauthenticated SQL injection in Sangoma Switchvox (VoIP PBX) actively exploited in the wild, leading to remote code execution. Attackers deploy reverse shells on exposed instances. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/ # CVE # Exploit # CyberSec

🤖 CVE-2026-9586: unauthenticated SQL injection in the Sangoma Switchvox VoIP platform, actively exploited in the wild to deploy reverse shells and achieve RCE. Patch and audit your PBX now. 🔗 https:

mastodon:infosec-exchangeother26d ago kagi ↗

🤖 CVE-2026-9586: unauthenticated SQL injection in the Sangoma Switchvox VoIP platform, actively exploited in the wild to deploy reverse shells and achieve RCE. Patch and audit your PBX now. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/ # CVE # RCE # CyberSec

Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that atta

mastodon:infosec-exchangeother26d ago kagi ↗

Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys. **If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed fro