<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials]]></title><description><![CDATA[<p dir="auto">Threat actors are actively exploiting a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform, to achieve unauthenticated remote code execution. The flaw, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9586" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-9586</a></strong> with a CVSS score of <strong>9.3</strong>, is a critical unauthenticated SQL injection issue present in <strong>Switchvox SMB Edition 8.3 (104997)</strong>.</p>
<p dir="auto">Successful exploitation allows attackers to execute arbitrary code without needing valid credentials. In observed campaigns, adversaries are leveraging this flaw to deploy reverse shells, establishing persistent remote access to affected systems.</p>
<ul>
<li>Affected product: Sangoma Switchvox SMB Edition 8.3 (104997)</li>
<li>Vulnerability type: Unauthenticated SQL injection leading to remote code execution</li>
<li>Observed impact: Deployment of reverse shells on compromised hosts</li>
</ul>
<p dir="auto">Organizations running this specific build should consider this a high-priority exposure, especially if the management interface is reachable from untrusted networks. Since exploitation does not require authentication, exposure to the internet significantly elevates risk.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given the unauthenticated nature of this flaw, how is your team validating that your Switchvox instances are either patched or isolated from external access?</p>
]]></description><link>https://xploitlk.com/topic/194/critical-attackers-exploit-critical-switchvox-flaw-to-deploy-reverse-shells-without-credentials</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:44 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/194.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 02 Sep 2026 22:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>