Attackers are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can enable remote code execution and reverse-shell access.
Security researchers at Horizon3 warn that most internet-facing Switchvox systems have already been scanned or attacked, and that additional exploitation attempts are likely to continue.
Sangoma Switchvox is an enterprise voice management platform used by organizations to configure, manage, and monitor business phone systems.
CVE-2026-9586 is the most severe of 12 vulnerabilities discovered by Horizon3 and reported to Sangoma on April 10. Sangoma addressed the security issues in Switchvox version 8.4.0.2, released on July 14.
The flaw is an unauthenticated SQL injection vulnerability affecting the /pa HTTP endpoint in Sangoma Switchvox. According to Horizon3, the publicly accessible endpoint processes XML messages containing specific key-value pairs.
When the /pa endpoint receives a notification from another phone system, such as an incoming or outgoing call event, it extracts the PhoneIP value from the XML request and inserts it directly into a non-parameterized SQL query.
Attackers can exploit this weakness remotely by sending specially crafted XML requests with curl. Researchers demonstrated that successful exploitation can be used to execute operating system commands on vulnerable Switchvox systems.

Source: Horizon3
On August 30, Horizon3 detected active exploitation attempts against multiple honeypots from a single source IP address, 176.65.148.184. The attacker attempted to establish a reverse shell on vulnerable Switchvox systems.
During the attacks, the threat actor executed an initial payload and collected information about the top processes running on the Switchvox device. The gathered data was then sent to a remote server in Base64-encoded form.
“Given the rapid succession of exploitation attempts across multiple honeypots from the same source IP, we believe it is likely that most Internet-facing Switchvox instances are targeted or have already been targeted,” Horizon3 warns.
“Currently, Shodan indicates there are approximately 4,000 devices on the internet, most of which are in the United States.”
Horizon3 has not observed active exploitation of the other 11 vulnerabilities it previously identified in Switchvox.
Because CVE-2026-9586 is being actively exploited, administrators should upgrade to Switchvox version 8.4.0.2 or later immediately. Organizations should also review systems for signs of compromise and suspicious activity.
Potential indicators of compromise include unusual entries in /var/log/switchvox/db-quirks.log and network connections to the attacker’s IP address, particularly on port 39323.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



