Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL-injection vulnerability in Sangoma Switchvox enterprise VoIP management systems. The flaw affects the unauthenticated /pa HTTP endpoint, where the PhoneIP field in an XML request is incorporated into an unparameterized PostgreSQL query, enabling remote code execution with PostgreSQL superuser privileges.
Sangoma fixed the issue in Switchvox 8.4.0.2. Researchers observed exploitation attempts against honeypots involving shell execution, process enumeration, and apparent collection of process information, indicating post-compromise reconnaissance and possible data exfiltration. Organizations should urgently identify internet-exposed Switchvox deployments, update to the patched release, and investigate logs and endpoint telemetry for suspicious requests to /pa and unexpected database- or shell-spawned processes; roughly 4,000 exposed instances were reportedly discoverable online, largely in the United States.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
CISA added Sangoma Switchvox vulnerability CVE-2026-9586 to its Known Exploited Vulnerabilities catalog following reports of active exploitation. The agency directed federal civilian agencies to remediate newly listed KEV vulnerabilities under its BOD 26-04 timelines.
Horizon3.ai observed exploitation attempts of CVE-2026-9586 beginning August 30 that targeted an estimated 4,000 internet-exposed Sangoma Switchvox instances, primarily in the United States.
During the August 30 exploitation attempts against Switchvox honeypots, the attacker established reverse shells, gathered top-running process information, and transmitted collected data to a remote server in base64-encoded form. Connections to 176.65.148.184, particularly over port 39323, were identified as potential indicators of compromise.
Defused Cyber honeypots recorded valid exploitation attempts against Switchvox systems. The activity included shell execution, process enumeration, and apparent collection of process information, with attempts observed from IP address 176.65.148.184.
CVE-2026-9586 was publicly published, documenting an unauthenticated SQL-injection flaw in Sangoma Switchvox SMB Edition's /pa endpoint that can be leveraged for remote code execution.
SRA published an advisory covering the Switchvox issues it had independently reported.
Sangoma released Switchvox version 8.4.0.2, which patched CVE-2026-9586, an unauthenticated SQL-injection vulnerability that can enable remote code execution.
SRA independently reported vulnerabilities affecting Sangoma Switchvox.
Horizon3 deployed internet-facing honeypots with Defused Cyber to monitor for zero-day exploitation of Switchvox vulnerabilities.
Sangoma provided Horizon3 with a pre-release patched build for vulnerability validation.
Horizon3 reported 12 vulnerabilities in Sangoma Switchvox, including the unauthenticated SQL-injection issue later designated CVE-2026-9586, to Sangoma. Sangoma acknowledged receipt the same day.
Additional technical reporting identified PhoneAppsHandler.pm as the vulnerable unauthenticated handler: it reportedly inserts the XML PhoneIP field into a SQL query without validation, with the query executing under PostgreSQL superuser privileges. The report also identified /var/log/switchvox/db-quirks.log as a log source that may contain evidence of compromise.
SRA disclosed reflected XSS (CVE-2026-9585), authenticated local file inclusion (CVE-2026-9587), and stored XSS in voicemail templates (CVE-2026-9588) affecting Switchvox SMB. The issues could enable session theft and authenticated actions, reading local files and secrets, or execution of stored scripts by users viewing affected voicemail templates.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
17 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourcecybersecuritynews.com
Open sourcelabs.sra.io
Open sourcecve.org
Open sourcesangomakb.atlassian.net
Open sourcehorizon3.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.