Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
An unauthenticated SQL injection in Sangoma's Switchvox VoIP platform (CVE-2026-9586) is being exploited in the wild to deploy reverse shells — a reminder that telephony infrastructure is often an unmonitored entry point.
Summary written by editorial AI · Source link below
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
Editorial Analysis
VoIP platforms are frequently treated as appliances and excluded from regular patching cycles, making them attractive targets for attackers seeking unmonitored network footholds.
Identify any Sangoma Switchvox deployments, apply available patches immediately, and segment VoIP infrastructure from critical network zones.
Attackers are exploiting a VoIP platform vulnerability to gain network access — verify your telephony systems are patched and segmented.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d