Active Exploitation Underway Against Sangoma Switchvox Flaw CVE-2026-9586

Active attacks are targeting internet-exposed Sangoma Switchvox unified communications instances via a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-9586.

Discovered in April 2026 by researchers at Horizon3 and independently by Security Risk Advisors, CVE-2026-9586 affects Sangoma Switchvox SMB Edition 8.3 and earlier versions. The vulnerability permits unauthenticated threat actors to submit crafted HTTP POST requests to an open endpoint, allowing arbitrary SQL execution against the underlying PostgreSQL database. Sangoma subsequently released version 8.4.0.2 on July 14, 2026, to remediate the issue.

In May 2026, Horizon3 deployed simulated internet honeypots mimicking Switchvox deployments in coordination with threat intelligence firm Defused Cyber. On August 30, honeypot telemetry recorded active exploitation attempts originating from a single source Internet Protocol address, 176.65.148.184, before expanding to dozens of additional scanning and payload-delivery sources.

Observed post-compromise activity includes the deployment of reverse shells, process enumeration commands, and second-stage malware installation consistent with cryptomining software. Analysts warn that roughly 4,000 vulnerable Switchvox appliances remain reachable on the public internet, predominantly in the United States.

Zach Hanley, researcher at Horizon3, noted the risk of lateral movement past perimeter defenses. “The Switchvox appliance is likely most valuable as a pivot point into organizations from external into internal networks. It is possible some appliances hold integration secrets that may allow them to pivot with stolen credentials,” Hanley stated via email.

Hanley added that researchers plan to maintain collaboration with Defused Cyber amid shifting threat dynamics. “With the increased capabilities of LLMs in the vulnerability discovery space, we believe that duplicate findings will be the norm and having insight into when they become known and exploited is valuable,” he said. Administrators unable to upgrade immediately are advised to restrict network access to Switchvox interfaces and the /pa endpoint.

Leave a Reply

Your email address will not be published. Required fields are marked *