< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Sangoma Switchvox vulnerability exploited for remote code execution

Security researchers at Horizon3 have identified a critical unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, in the Sangoma Switchvox VoIP management platform. The flaw exists within the /paHTTP endpoint, where the system fails to sanitize the PhoneIP field from XML messages before incorporating it into a PostgreSQL query.

Exploitation of this vulnerability allows remote attackers to execute arbitrary SQL statements and achieve remote code execution (RCE) on the affected system. On August 30, 2026, active exploitation was observed targeting Switchvox honeypots. In these instances, attackers attempted to establish reverse shells and enumerate running processes to collect system information.

The vulnerability carries a CVSS 4.0 score of 9.3. Sangoma has released a patch to address these issues in Switchvox version 8.4.0.2, which was issued on July 14.

Entities

Everest Forms Pro · GeoNetwork · Horizon3 · PostgreSQL · Sangoma · ServiceNow · Switchvox

Claims

What the coverage asserts, and how many sources carry each claim.

  • [● 2 SOURCES] CVE-2026-9586 allows unauthenticated SQL injection and remote code execution via the /paHTTP endpoint. horizon3.ai · cybernoz.com
  • [○ 1 SOURCE] The attacker used the IP address 176.65.148.184 to target Switchvox instances. cybernoz.com
  • [● 2 SOURCES] Exploitation of CVE-2026-9586 against Switchvox honeypots was observed on August 30, 2026. horizon3.ai · cybernoz.com
  • [● 2 SOURCES] Horizon3 discovered CVE-2026-9586 in Sangoma Switchvox SMB Edition 8.3. horizon3.ai · cybernoz.com
  • [● 2 SOURCES] The vulnerability has a CVSS 4.0 score of 9.3 Critical. horizon3.ai · cybernoz.com
  • [○ 1 SOURCE] Sangoma released a fix in Switchvox version 8.4.0.2 on July 14. cybernoz.com