Threat actors are actively exploiting a critical security vulnerability in Sangoma Switchvox, an enterprise Voice over IP (VoIP) platform, that could allow unauthenticated attackers to execute remote code without requiring valid credentials. The vulnerability, tracked as CVE-2026-9586 with a CVSS score of 9.3, affects Sangoma Switchvox SMB Edition 8.3 (104997) and allows attackers to perform SQL injection attacks that can lead to arbitrary code execution with PostgreSQL superuser privileges. Sangoma released security patches for the issue in Switchvox version 8.4.0.2 on July 14, 2026.
The vulnerability exists in the /pa endpoint of Switchvox, where XML content beginning with <PolycomIPPhone> processes user controlled PhoneIP values. According to the vulnerability description published on CVE.org, the affected endpoint directly combines user supplied input into PostgreSQL database queries without proper sanitization or parameter handling. This allows an unauthenticated remote attacker to send specially crafted requests and execute arbitrary SQL statements against the backend database, including database operations and remote code execution. Horizon3.ai reported that CVE-2026-9586 was among 12 vulnerabilities reported to Sangoma in April 2026 and confirmed that active exploitation attempts against the flaw started on August 30, 2026. Researchers estimate that around 4,000 Switchvox instances are exposed to the internet, with most located in the United States.
Security Risk Advisors (SRA) Labs independently discovered and reported the vulnerability in May 2026. Researchers demonstrated that an unauthenticated attacker could perform database operations, extract database information, modify user records, and increase privileges to Switchvox web administrator accounts. SRA Labs also confirmed that successful exploitation could allow attackers to execute arbitrary code on affected servers and establish reverse shell access. In one demonstrated scenario, exploitation of CVE-2026-9586 allowed the extraction of the cookie signing key to an external server, which could enable attackers to create authentication material for different users. Horizon3.ai observed exploitation activity against its honeypots involving deployment of reverse shells on compromised systems followed by Base64 encoded commands used to identify running processes. Researchers identified indicators of compromise, including SQL injection activity recorded in /var/log/switchvox/db-quirks.log on systems with SSH access enabled. An attacker IP address linked to the activity, 176.65.148[.]184, has also been flagged on VirusTotal for port scanning, brute force attempts, and exploitation activity.
Researchers warned that the speed and consistency of exploitation attempts from the same source IP indicate that many internet exposed Switchvox systems may already have been targeted or could become targets. Zach Hanley, a security researcher, said the repeated exploitation attempts across multiple honeypots suggest that organizations using publicly accessible Switchvox deployments should review their systems for signs of compromise. The vulnerability highlights the risks associated with exposed enterprise communication platforms that process external requests. Organizations using affected versions of Sangoma Switchvox are advised to apply available security updates and review logs, endpoint activity, and network traffic for suspicious behavior. Security teams should also investigate potential reverse shell activity and unauthorized database changes to determine whether systems have been affected by exploitation attempts.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.