Remote Code Execution Flaw in Sangoma Switchvox Actively Exploited, Researchers Warn
A critical vulnerability identified as CVE-2026-9586 is being leveraged by attackers to gain unauthenticated access to Sangoma Switchvox phone systems, allowing arbitrary code execution on affected installations.
The flaw stems from an SQL injection weakness in the Switchvox management interface that does not require any credentials. By injecting crafted queries, threat actors can manipulate the underlying database and trigger the execution of malicious payloads, potentially compromising entire corporate telephony environments.
SecurityWeek first reported the issue after observing signs of active exploitation in the wild. Network traffic analyses and intrusion detection logs from several organizations showed repeated attempts to exploit the injection point, confirming that the vulnerability is not merely theoretical but is being used in real‑world attacks.
Switchvox, a popular unified communications platform used by small and medium‑sized businesses, integrates voice, messaging, and video services. Compromise of the system can give attackers control over call routing, enable eavesdropping, or serve as a foothold for further lateral movement within a network, raising concerns for both operational continuity and data privacy.
In response, Sangoma has issued an advisory urging administrators to apply the latest security patches, which address the SQL injection vector and tighten input validation. The company also recommends restricting external access to the management console, employing strong network segmentation, and monitoring for anomalous database queries.
Cybersecurity experts advise organizations that rely on Switchvox to verify their patch levels immediately and to review firewall rules that expose the management interface to the internet. As the vulnerability remains actively exploited, timely mitigation is essential to prevent potential disruption of voice services and the broader security implications of a compromised telephony infrastructure.
Comments (0)
Be the first to comment.
Join the discussion