Hackers Leverage Sangoma Switchvox SQL Flaw to Install Remote Shells
Security researchers have confirmed that threat actors are actively weaponising a critical vulnerability in Sangoma's Switchvox VoIP platform, identified as CVE-2026-9586. The flaw allows unauthenticated users to inject malicious SQL commands, ultimately granting the ability to execute arbitrary code on affected servers and open reverse shells for persistent access.
The issue stems from insufficient input validation in the platform's web interface, which processes user-supplied data without proper sanitisation. By crafting a specially‑formed request, an attacker can manipulate the underlying database, inject commands, and trigger the execution of a payload that connects back to a remote controller. Because the exploit requires no valid credentials, it can be launched against any publicly reachable Switchvox installation.
Switchvox, a popular on‑premise solution for business telephony, is deployed by thousands of small and medium‑size enterprises worldwide. Its integration with existing phone networks and support for features such as call routing, voicemail, and video conferencing make it a common target for cyber‑crime groups seeking to hijack communications or use compromised servers as footholds within corporate networks.
Sangoma has issued an advisory urging administrators to apply the latest security patch, which addresses the SQL injection vector and hardens the platform against unauthorised database queries. The vendor also recommends disabling external access to the management console where possible, enforcing strong network segmentation, and monitoring for unusual outbound connections that may indicate a reverse‑shell attempt.
Industry analysts note that the rapid exploitation of CVE-2026-9586 reflects a broader trend of attackers focusing on VoIP infrastructure, which often lacks the same level of scrutiny as traditional IT systems. As organisations continue to rely on unified communications for remote work, the exposure of such critical flaws underscores the need for regular vulnerability assessments and timely patch management. Until the majority of installations are updated, security teams should remain vigilant for indicators of compromise, including unexpected processes, anomalous traffic to unknown IP addresses, and irregular call‑handling behaviour.
Comments (0)
Be the first to comment.
Join the discussion