Back to Feed
VulnerabilitiesSep 2, 2026

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Attackers exploit critical CVE-2026-9586 in Sangoma Switchvox for unauthenticated RCE.

Summary

Threat actors are actively exploiting a critical SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3. This flaw allows unauthenticated attackers to execute arbitrary code as the PostgreSQL superuser, leading to reverse shells and potential cookie signing key exfiltration. Sangoma released patches in July 2026, but an estimated 4,000 internet-exposed instances remain vulnerable.

Full text

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials Ravie LakshmananSep 02, 2026Vulnerability / Network Security Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026. "An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization," according to a description of the flaw on CVE.org. "An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution." Horizon3.ai said CVE-2026-9586 is among the 12 distinct vulnerabilities in Switchvox that were reported to Sangoma in April 2026, and that it is now seeing valid exploitation attempts in the wild against the flaw starting August 30, 2026. There are about 4,000 instances exposed to the internet, most of them located in the U.S. The same vulnerability was independently discovered and reported by Security Risk Advisors (SRA) Labs in May. "As an unauthenticated attacker, we were able to perform arbitrary database operations, including extracting database contents, modifying user records, and escalating privileges to Switchvox web administrators," SRA Labs said. "We also successfully executed arbitrary code on the server, invoking a reverse shell on the target machine." In one example highlighted by SRA Labs, successful exploitation of CVE-2026-9586 makes it possible to exfiltrate the cookie signing key to an external server, thereby allowing an attacker to forge authentication material for arbitrary users. The exploitation efforts targeting its honeypots involve the deployment of reverse shells on compromised systems, followed by running Base64-encoded commands to enumerate running processes. The autonomous penetration testing platform has shared the following indicators of compromise - On devices that have SSH access enabled, evidence of the SQL injection payload used can be observed in "/var/log/switchvox/db-quirks.log" Attacker IP address "176.65.148[.]184" It's worth noting that the IP address has been flagged on VirusTotal for conducting port scanning, brute-force, and exploitation efforts. "Given the quick succession of exploit attempts across multiple honeypots from the same source IP, we believe that it is likely that most internet exposed Switchvox instances will be or have already been targeted," security researcher Zach Hanley said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  network security, Vulnerability, Web Security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Indicators of Compromise

  • cve — CVE-2026-9586
  • ip — 176.65.148.184

Entities

Switchvox SMB Edition 8.3 (104997) (product)Sangoma (vendor)SQL injection (technology)Reverse Shell (technology)