Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Attackers actively exploit SQL injection flaw CVE-2026-9586 in unauthenticated Sangoma Switchvox endpoints, dropping reverse shells and second-stage cryptominer malware.
CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox SMB Edition 8.3, lets crafted HTTP POST requests execute arbitrary SQL against the backend PostgreSQL database. Horizon3 honeypots first saw exploitation on August 30, 2026 from IP 176.65.148.184, and dozens of additional source IPs have since joined with scanning payloads and second-stage malware that appears to be a cryptominer. The flaw was patched in Switchvox 8.4.0.2 on July 14, 2026; roughly 4,000 exposed instances exist, mostly in the United States, and exploitation is likely against most of them.
- Unauthenticated HTTP POST to the /pa endpoint enables arbitrary SQL execution.
- Attacker deploys reverse shells and enumerates running processes on compromised hosts.
- Second-stage malware observed appears to be a cryptominer; more source IPs now exploiting.
- Appliance may serve as pivot point using stored integration credentials.
- Restrict network access to Switchvox interfaces if patching to 8.4.0.2 is not possible.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9586 | Unauthenticated SQL Injection RCE in Sangoma Switchvox SMB Edition Sangoma Switchvox SMB Edition 8.3 (build 104997) contains an unauthenticated SQL injection flaw (CWE-89) in its /pa endpoint, where the user-controlled PhoneIP value from XML input is concatenated directly into PostgreSQL queries without sanitization or parameterization. A single crafted request lets a remote, unauthenticated attacker execute arbitrary SQL statements against the backend PostgreSQL database, which can be escalated to remote code execution on the server. Any organization running the affected Switchvox SMB Edition build is exposed, especially appliances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2026-09-02, and researchers have observed attackers using it without credentials to deploy reverse shells and cryptocurrency miners. Do: Identify all Switchvox SMB Edition deployments and verify the running build (affected: 8.3, build 104997), then upgrade to the patched release specified in Sangoma's advisory. If patching is delayed, restrict or remove internet exposure of the Switchvox web interface, including the /pa endpoint. Hunt for indicators of compromise such as unexpected reverse shells, new processes, or crypto-miner activity, as active exploitation is confirmed and the flaw is on CISA's KEV catalog, making it subject to BOD 26-04 patching guidance for federal stakeholders. | 9.3 | 12% | KEV PoC |
| moderatelikely on the order of thousands of on-prem PBX deployments (est.) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 176.65.148.184 | include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across mu |
Full article495 words · extracted from helpnetsecurity.com · click to collapse
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately.

How CVE-2026-9586 works
Switchvox is a VoIP-based unified communications platform built on the open-source Asterisk engine and aimed at small and medium-size businesses. It can be deployed on-premises, in the cloud, or on virtualized infrastructure.
CVE-2026-9586, found in Sangoma Switchvox SMB Edition 8.3, allows attackers to send a specially crafted HTTP POST request to an endpoint that doesn’t require authentication, and thus execute arbitrary SQL statements against the backend PostgreSQL database.
The vulnerability was discovered in April 2026 by Horizon3 researchers and (independently, a bit later) by Security Risk Advisors. Both reported it and other unearthed flaws to Sangoma, and CVE-2026-9586 was patched in Switchvox version 8.4.0.2, released on July 14, 2026.
Horizon3 deployed internet honeypots mimicking systems running Switchvox in coordination with threat intelligency company Defused Cyber in May 2026 – before Sangoma shipped fixes – to monitor for exploitation of the discovered vulnerabilities.
On August 30, the honeypots started seeing exploitation attempts against CVE-2026-9586.
What the attacker is doing
The attempts came from a single IP address. The attacker drops reverse shells on compromised systems and then runs commands to enumerate running processes.
The indicators of compromise outlined by Horizon3 researcher Zach Hanley include specific log entries and the attackers’ IP address (176.65.148.184).
“Given the quick succession of exploit attempts across multiple honeypots from the same source IP, we believe that it is likely that most internet exposed Switchvox instances will be or have already been targeted,” he warned.
“Currently Shodan shows that there are approximately 4,000 devices on the internet, with most located within the United States.”
Switchvox users who can’t update their instance to a fixed version should restrict network access to the Switchvox interfaces and the /pa endpoint.
UPDATE (September 2, 2026, 02:45 p.m. ET):
“The Switchvox appliance is likely most valuable as a pivot point into organizations from external into internal networks. It is possible some appliances hold integration secrets that may allow them to pivot with stolen credentials,” Zach Hanley told Help Net Security via email.
But the threat actor is currently after something else: since the initial observations, the same threat actor has been observed downloading second-stage malware onto the system, which on a cursory look appeared to be a cryptominer, he shared.
Also, since his post was published, dozens of additional source IPs have been observed exploiting the honeypots to include simple scanning payloads and also more second stage malware installation.
Hanley said that Horizon3 plans to continue the collaboration with Defused Cyber: “With the increased capabilities of LLMs in the vulnerability discovery space, we believe that duplicate findings will be the norm and having insight into when they become known and exploited is valuable.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/