Hackers Exploit Critical Sangoma Switchvox SQL Injection Flaw for Unauthenticated RCE
Brief
Threat actors are actively attempting to exploit CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that can be escalated to remote code execution.
Researchers at Horizon3.ai said internet-facing honeypots run alongside Defused Cyber captured valid exploitation attempts on August 30, several weeks after Sangoma released security fixes for the enterprise VoIP platform.
Sangoma Switchvox is an on-premises telephony management solution used by organizations to configure business phone systems, voicemail, call forwarding, device provisioning, call monitoring, and analytics.
Critical Sangoma Switchvox SQL Injection Flaw
The vulnerability affects an unauthenticated HTTP endpoint, /pa , which is designed to handle phone notification events for supported devices.
According to Horizon3. ai , the issue exists in the Perl-based PhoneAppsHandler.
