ZeroHour
Horizon3.aipublished ()ingested Zach Hanley

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586

highExploit / PoC exploited in the wildimportance 72CVE-2026-9586
AI summary · glm-5.3-flash

Horizon3 disclosed CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox leading to RCE, now under active exploitation in the wild.

Horizon3.ai attack researchers discovered CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma's Switchvox VoIP appliance that can escalate to remote code execution. The researchers observed active exploitation of the flaw in the wild. A disclosure write-up was published alongside their findings, and defenders should treat internet-exposed Switchvox instances as at risk.

  • Unauthenticated SQL injection chains to remote code execution
  • Active exploitation observed in the wild by Horizon3
  • Impacts Sangoma Switchvox VoIP appliance users
  • No authentication required for exploitation

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-9586
Unauthenticated SQL Injection RCE in Sangoma Switchvox SMB Edition

Sangoma Switchvox SMB Edition 8.3 (build 104997) contains an unauthenticated SQL injection flaw (CWE-89) in its /pa endpoint, where the user-controlled PhoneIP value from XML input is concatenated directly into PostgreSQL queries without sanitization or parameterization. A single crafted request lets a remote, unauthenticated attacker execute arbitrary SQL statements against the backend PostgreSQL database, which can be escalated to remote code execution on the server. Any organization running the affected Switchvox SMB Edition build is exposed, especially appliances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2026-09-02, and researchers have observed attackers using it without credentials to deploy reverse shells and cryptocurrency miners.

Do: Identify all Switchvox SMB Edition deployments and verify the running build (affected: 8.3, build 104997), then upgrade to the patched release specified in Sangoma's advisory. If patching is delayed, restrict or remove internet exposure of the Switchvox web interface, including the /pa endpoint. Hunt for indicators of compromise such as unexpected reverse shells, new processes, or crypto-miner activity, as active exploitation is confirmed and the flaw is on CISA's KEV catalog, making it subject to BOD 26-04 patching guidance for federal stakeholders.

9.312% KEV PoC
  • Sangoma Switchvox SMB Edition 8.3 (build 104997)
moderatelikely on the order of thousands of on-prem PBX deployments (est.)
Full article

Horizon3 researchers discovered CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox that leads to remote code execution and is now being actively exploited.

This source does not provide full text. Read it at horizon3.ai.