Image: Horizon3
- CVE: CVE-2026-9586
- CVSS: 9.3 (Critical · CVSSv4)
- Product: Sangoma Switchvox SMB Edition
- Affected: 8.3 (104997)
- Impact: Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
- Status: Exploited in the wild
- Patched in: 8.4.0.2
- EPSS: 0.4% (30-day)
- Action: Update to 8.4.0.2 now
TL;DR
Attackers are exploiting CVE-2026-9586 in the wild. This critical Sangoma Switchvox vulnerability turns an unauthenticated SQL injection into remote code execution. Horizon3 confirmed valid exploitation attempts and urges an immediate upgrade.
Why It Matters
Switchvox is an enterprise VoIP telephony platform used to manage phone systems. Therefore, a pre-auth flaw exposes voice infrastructure to full takeover. A successful attack runs code as the PostgreSQL superuser.
Horizon3 found the bug while auditing Sangoma after related FreePBX flaws hit the CISA KEV catalog. In their words, they reported “12 distinct vulnerabilities in the Switchvox product”. This one proved the most severe.
How the Attack Works
Switchvox exposes an unauthenticated HTTP endpoint at /pa. That endpoint parses an XML message from supported phones. According to Horizon3, the PhoneIP field is “directly concatenated into an unparameterized SQL query”.
As a result, an attacker injects SQL through that field. The query then runs with database superuser rights. From there, the attacker reaches command execution and a reverse shell. This report withholds the payload details.
Exploitation Status
Horizon3 confirms active exploitation of this Sangoma Switchvox vulnerability. Their honeypots captured real attack traffic from a single source IP. Independent researchers at SRA Labs first disclosed the flaw class in July 2026.
Shodan shows roughly 4,000 exposed instances, most located in the United States. Consequently, Horizon3 expects most internet-facing devices to be targeted.
Affected Versions
The flaw affects Sangoma Switchvox before version 8.4.0.2. SRA Labs traced the issue to the 8.3 build during testing.
Patch and Mitigation Steps
Sangoma fixed the issue in Switchvox 8.4.0.2. Admins should upgrade now using the Switchvox 8.4.0.2 release notes. Until then, block public access to the /pa endpoint. Also check db-quirks.log and hunt for the attacker IP 176.65.148.184.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!