logo

Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection

ID: e59d31e8-8c19-5b7a-b1c0-b5b57fe28b3e

STIX ID: report--e59d31e8-8c19-5b7a-b1c0-b5b57fe28b3e

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Divya

...
...

Security researchers observed active exploitation of CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox that allows remote code execution via the PhoneAppsHandler.pm XML endpoint; attackers have been seen attempting shell execution and data collection against internet-exposed devices (Horizon3.ai honeypots), with one observed attacker IP 176.65.148.184. Administrators are advised to upgrade to Switchvox 8.4.0.2, restrict management-plane exposure (VPN/trusted controls), monitor logs (e.g., /var/log/switchvox/db-quirks.log) for suspicious SQL/curl/netcat activity, and treat internet-facing unpatched devices as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.