TechNewsReel
Live

Attackers Exploit Critical RCE Flaw in Sangoma Switchvox VoIP Platform

A critical unauthenticated SQL injection vulnerability in Switchvox SMB Edition allows remote actors to seize full control of communication servers.

TechNewsReel Newsroom · September 2, 2026

Threat actors are actively exploiting a critical security flaw in Sangoma Switchvox that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability, tracked as CVE-2026-9586, enables attackers to bypass security controls and gain full system access without valid credentials.

The flaw is an unauthenticated SQL injection vulnerability specifically affecting Sangoma Switchvox SMB Edition 8.3 (104997). According to reports from The Hacker News, attackers are leveraging this vulnerability to execute arbitrary SQL statements, which in turn facilitates remote code execution (RCE). In observed wild attacks, threat actors have used this path to deploy reverse shells, granting them complete administrative control over the target VoIP platform.

The VoIP Attack Surface

Sangoma Switchvox is an enterprise-grade VoIP platform designed for business communication management. Because these platforms typically utilize web-facing management interfaces to allow administrators to configure phone systems, they are frequent targets for SQL injection. When such a flaw exists, it provides a direct conduit from the public internet into the heart of a company's internal server environment, bypassing the need for a perimeter breach or stolen passwords.

Risks to Corporate Infrastructure

This vulnerability is particularly dangerous because VoIP servers are not isolated islands; they handle sensitive voice data, maintain detailed call logs, and are deeply integrated into internal corporate networks. A successful RCE attack does more than compromise a phone system. Once an attacker establishes a reverse shell on the Switchvox server, they can use the machine as a pivot point. This allows them to move laterally through the network, intercepting internal communications or launching further attacks against other critical internal infrastructure.

Remediation and Outlook

Sangoma has addressed the vulnerability in a newer release. The flaw was patched in Switchvox version 8.4.0.2, and administrators are urged to update their systems immediately to close the exploit window. Security teams should monitor for unusual outbound connections from their VoIP infrastructure, which may indicate the presence of an active reverse shell. While the primary exploit vector is now patched, the active exploitation of CVE-2026-9586 underscores the ongoing risk posed by legacy management interfaces in communication hardware.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.