logo

Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks

ID: afc577b3-c33c-5896-9a41-1b044763603d

STIX ID: report--afc577b3-c33c-5896-9a41-1b044763603d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-09-03

Date Updated: 2026-09-16

Author: Abinaya

...
...

A critical unauthenticated SQL injection vulnerability (CVE-2026-9586, CVSS 9.3) in Sangoma Switchvox SMB Edition allows remote command execution via an XML endpoint (/pa) that processes PhoneIP values without proper sanitization. Horizon3.ai and Defused Cyber observed active exploitation beginning August 30, 2026, including reverse shell attempts and Base64-encoded post-exploitation reconnaissance from IP 176.65.148.184; ~4,000 Switchvox devices were identified as internet-exposed. Sangoma released Switchvox 8.4.0.2 to address the issue; administrators are advised to patch, audit db-quirks.log for suspicious SQL, investigate connections to the attacker IP, and restrict access to the /pa endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.