- Unauthenticated SQL injection in Sangoma Switchvox /pa endpoint leading to RCE
176.65.148.184Attacker IP observed conducting active exploitation attempts on multiple Switchvox honeypots on August 30
The cybersecurity landscape continues to face active exploitation of critical vulnerabilities across multiple platforms. Today's briefing covers urgent threats affecting VoIP infrastructure, edge security devices, WordPress installations, and the takedown of a persistent botnet operation that evaded disruption for over two decades.
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that enables remote code execution. The vulnerability allows threat actors to gain unauthorized access to affected systems and deploy reverse shells for persistent command and control. This active exploitation represents an immediate risk to organizations relying on Sangoma Switchvox for their telecommunications infrastructure.
Source: Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
SonicWall's SMA 1000 edge device has been targeted by exploitation activity involving zero-day vulnerabilities that permit unauthenticated remote code execution. This campaign follows earlier attacks during the summer targeting two additional zero-day flaws in the vendor's edge device portfolio. The recurring exploitation of SonicWall edge appliances indicates a sustained focus by threat actors on perimeter security infrastructure.
Source: SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
An SQL injection vulnerability tracked as CVE-2026-19949 has been discovered in the All-in-One WP Migration and Backup plugin for WordPress. The flaw permits unauthenticated attackers to execute remote code and assume complete control of affected websites. With millions of WordPress installations relying on this backup plugin, the vulnerability poses a significant supply chain risk to a substantial portion of the web.
Source: WordPress backup plugin flaw exposes millions of sites to takeover attacks
The Sality botnet, a Russia-based peer-to-peer malware operation, has been successfully dismantled following an exceptional 23-year operational period. The botnet's distributed infrastructure allowed it to evade system-wide disruption efforts for an unusually prolonged timeframe before authorities and cybersecurity experts finally achieved its takedown. This operation represents one of the longest-running botnet campaigns in recorded history.
Source: Dogged Russia-based botnet dismantled after 23-year run
Organizations should prioritize patching the identified vulnerabilities in Sangoma Switchvox, SonicWall SMA 1000, and WordPress backup plugins while maintaining vigilance for any indicators of compromise related to these active exploitation campaigns.
Source articles and extracted indicators (defanged where appropriate).
176.65.148.184