CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP systems, was actively exploited in the wild by 3 September 2026. Security researchers at Defused Cyber and Horizon3 documented reverse-shell deployments affecting approximately 4,000 internet-exposed systems.
11 reportsother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Honeypot data confirms active exploitation of Sangoma Switchvox RCE vulnerability CVE-2026-9586, affecting ~4,000 internet-exposed systems. Defused Cyber recorded reverse shells and https:// deafnews.it/en/article/honeypo t-confirms-active-exploitation-of-sangoma-switchvox-rce
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https:// horizon3.ai/attack-research/di sclosures/cve-2026-9586-sangoma-switchvox-rce/
Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. # Switchvox # SqlInjection # ThreatIntel https:// cyberworldops.eu/en/switchvox- under-at
🔴 EXPLOITED Sangoma Switchvox has a critical unauthenticated flaw (CVE-2026-9586, CVSS 9.3) that lets a stranger run code on the phone system. Patched in July, mass-exploited since Aug 30. Around 4,000 consoles are exposed. Fix: update to 8.4.0.2 and hunt the logs. https:// suriq.io/blog/switchvox-cve-20 26-9586-unauth-rce-exploited # CVE # infosec # cybersecurity
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. https://www. bleepingcomputer.com/news/secu rity/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/
🤖 CVE-2026-9586: unauthenticated SQL injection in the Sangoma Switchvox VoIP platform, actively exploited in the wild to deploy reverse shells and achieve RCE. Patch and audit your PBX now. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/ # CVE # RCE # CyberSec
Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys. **If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed fro