🔴 Critical: Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
-
Threat actors are actively exploiting a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform, to achieve unauthenticated remote code execution. The flaw, tracked as CVE-2026-9586 with a CVSS score of 9.3, is a critical unauthenticated SQL injection issue present in Switchvox SMB Edition 8.3 (104997).
Successful exploitation allows attackers to execute arbitrary code without needing valid credentials. In observed campaigns, adversaries are leveraging this flaw to deploy reverse shells, establishing persistent remote access to affected systems.
- Affected product: Sangoma Switchvox SMB Edition 8.3 (104997)
- Vulnerability type: Unauthenticated SQL injection leading to remote code execution
- Observed impact: Deployment of reverse shells on compromised hosts
Organizations running this specific build should consider this a high-priority exposure, especially if the management interface is reachable from untrusted networks. Since exploitation does not require authentication, exposure to the internet significantly elevates risk.
Source: The Hacker News
Given the unauthenticated nature of this flaw, how is your team validating that your Switchvox instances are either patched or isolated from external access?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login