60
60
57
60
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
Horizon3 disclosed CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox leading to RCE, now under active exploitation in the wild.
Horizon3.ai attack researchers discovered CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma's Switchvox VoIP appliance that can escalate to remote code execution. The researchers observed active exploitation of the flaw in the wild. A disclosure write-up was published alongside their findings, and defenders should treat internet-exposed Switchvox instances as at risk.
72
57
60
60
60
57
57
57
60
57
57
60
60
60
57
60
57
60
60
60
60
57
60
60
60
60
60
57
57
57
57
60
60
57
57
60