← All articles

Exploited Sangoma Switchvox flaw gives unauthenticated attackers reverse shells

Attackers are exploiting a critical flaw in Sangoma Switchvox, a widely used enterprise VoIP phone-system platform, to run code on servers without any credentials. Tracked as CVE-2026-9586 and scored 9.3, it is an unauthenticated SQL injection in an internet-facing endpoint that concatenates user-controlled input directly into database queries, letting an attacker execute commands as the database superuser and drop a reverse shell. Researchers at Horizon3 saw exploitation begin on August 30 and warn that most of the roughly 4,000 internet-exposed Switchvox systems may already have been targeted. Sangoma patched the flaw in version 8.4.0.2 back in July, but many systems remain unpatched and reachable.

Check
Update Sangoma Switchvox to 8.4.0.2 or later immediately, and because exploitation is active, review logs for the published indicators, reverse-shell activity, and process-enumeration commands on exposed systems.
Affected
Organizations running internet-exposed Sangoma Switchvox before 8.4.0.2 (CVE-2026-9586); an unauthenticated attacker can inject SQL, execute commands as the database superuser, gain a reverse shell, and take over the phone system.
Fix
Patch to 8.4.0.2, take the management interface off the public internet, hunt for reverse shells and unauthorized database changes, rotate credentials, and treat any exposed unpatched instance as potentially already compromised.