< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-09-02T12:38:50+05:30

Critical Switchvox Vulnerability Exploited for Unauthenticated Reverse Shell Deployment

A critical unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox allows attackers to execute arbitrary code as the PostgreSQL superuser without credentials. Exploitation attempts have been observed in the wild, enabling reverse shell deployment and database access on exposed systems.

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.

The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as

Read original article

*** END OF TRANSMISSION ***