← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 3, 2026 · 10:59via Cyber Security News

Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks

Brief

A critical vulnerability in Sangoma Switchvox is being actively exploited , affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics.

The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on vulnerable systems without needing valid credentials.

Horizon3.ai researchers observed valid exploitation attempts against internet-exposed Switchvox devices on August 30, 2026, with attackers attempting to deploy reverse shells for remote command-line access to compromised VoIP servers .

CVE-2026-9586 is an unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition 8. 3, build 104997, and earlier releases. The issue has a CVSS severity score of 9. 3 and can lead to remote code execution.

Read more on Cyber Security News