CVE-2026-9586

Published Jul 17, 2026

Last updated 10 days ago

Exploit knownCVSS critical 9.3
PostgreSQL
SQL injection
Sangoma Switchvox SMB Edition

Overview

Description
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Source
57dba5dd-1a03-47f6-8b36-e84e47d335d8
NVD status
Analyzed
Products
switchvox

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Sangoma Switchvox SQL Injection Vulnerability
Exploit added on
Sep 2, 2026
Exploit action due
Sep 5, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

57dba5dd-1a03-47f6-8b36-e84e47d335d8
CWE-89

Social media

Hype score
Not currently trending
  1. 🐦 🚨 Unpatched Magento/Adobe Commerce zero-day ("StyleSmuggler") actively exploited for unauthenticated RCE — no CVE, no patch yet. Also active: Sangoma Switchvox CVE-2026-9586 (CVSS 9.3) unauth SQLi to RCE, patch 8.4.0.2. #infosec #0day #CVE

    @ita_ipo

    6 Sept 2026

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https://t.co/jDAqoIxQoY #patchmanagement

    @eyalestrin

    5 Sept 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Sangoma Switchvox CVE-2026-9586 exploited in the wild: unauthenticated SQL injection leads to RCE. Patch and hunt for IoCs now. #CyberSecurity #Switchvox #InfoSec https://t.co/Q2fAdSXHYw

    @CyberWorldOps

    5 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔴 Sangoma Switchvox PBX under active attackAttackers are exploiting CVE-2026-9586 (CVSS 9.3) — an unauthenticated SQL injection that can lead to RCE. Reverse-shell attempts are already being https://t.co/xDyt4ErneF #CVE #CVE20269586 #Sangoma #Switchvox #PBX #RCE #CyberSecuri

    @stem__shop

    5 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔒 #CyberSecurity CVE-2026-9586: Sangoma Switchvox Unauthenticated SQL Injection Exploited in the… "If you run Sangoma Switchvox anywhere on your network — and especially if its web…" 🔗 https://t.co/zrWz9Erddc #CyberSecurity #ThreatIntel #critical #zeroday #cve

    @SecurityAr58409

    5 Sept 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Sangoma Switchvox Açığı Aktif İstismarda CVE-2026-9586 (CVSS 9.3), kimlik doğrulaması olmadan uzaktan SQL injection ve RCE yapılmasına izin veriyor. Açık saldırılarda aktif olarak kullanılıyor. Switchvox 8.4.0.2+ sürümüne güncelleyin. #CVE #VoIP #SiberG

    @KubbeSiber

    4 Sept 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Sangoma Switchvox'taki kritik açık sömürülmeye başlandı! CVE-2026-9586, kurumsal VoIP telefon santrali Switchvox'ta kimlik doğrulaması istemeyen /pa uç noktasından SQL enjeksiyonu ve uzaktan kod çalıştırma sağlıyor. https://t.co/OJgtVc4iPP https://t.co/UT0Mu9b

    @Siber_Bulten

    4 Sept 2026

    371 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CISA Adds Exploited Sangoma Switchvox SQL Injection (CVE-2026-9586) to KEV Catalog Critical Vulnerability Alert! Sangoma Switchvox is affected by CVE-2026-9586. 🔍 Identify Targets via ZoomEye: Search Dork: app="Sangoma Switchvox" Exposure: 240 instances identified http

    @zoomeyebot

    4 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Recent zero-days found in SonicWall SMA 1000 appliances (CVE-2026-83548/9) and Sangoma Switchvox (CVE-2026-9586) enable unauthenticated RCE, severely impacting data privacy &amp; integrity in transit. Patch immediately! #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    4 Sept 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔴 𝗖𝗥𝗜𝗧𝗜𝗖𝗔𝗟 · 𝗭𝗲𝗿𝗼 𝗱𝗮𝘆 🏢 Target: 𝗦𝗮𝗻𝗴𝗼𝗺𝗮 🧩 Product: 𝗦𝘄𝗶𝘁𝗰𝗵𝘃𝗼𝘅 A critical vulnerability (CVE-2026-9586) in Sangoma Switchvox allows unauthenticated remote code execution via spe

    @intels_daily

    4 Sept 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Sangoma Switchvox SQL Injection (CVE-2026-9586): Critical Unauthenticated RCE Risk A critical SQL injection vulnerability in Sangoma Switchvox (CVE-2026-9586) allows unauthenticated attackers to execute… Full write-up → link in bio #cybersecurity #infosec #cve #kev #sangoma

    @HotaSamit

    3 Sept 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Active exploitation of CVE-2026-9586 in Sangoma Switchvox is dropping reverse shells and staging malware on internet-exposed systems. Patch 8.4.0.2 and review indicators of compromise. #Switchvox #CVE20269586 #Asterisk https://t.co/40uVYNKyeA

    @TweetThreatNews

    3 Sept 2026

    263 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CISAが既知の悪用された脆弱性7件をカタログに追加 #CISA (Sep 2) CVE-2026-9586 Sangoma SwitchvoxのSQLインジェクション脆弱性 CVE-2026-48710 Kludex Starlette HTTPリクエスト/レスポンスの密輸脆弱性 CVE-2026-49869 Kestra OSS OSのコマ

    @foxbook

    3 Sept 2026

    263 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. ⚠️ ثغرة حقن قواعد بيانات في سويتشفوكس تُستغل فعلياً لنشر أصداف عكسية على نحو 4000 نظام مكشوف. المعرّف : CVE-2026-9586 درجة الخطورة : 9.3 (CVSS) - Critical الإصدارات المتأ

    @KasperskyDev

    3 Sept 2026

    163 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 Cerca de 4.000 sistemas #SangomaSwitchvox están expuestos a Internet y una falla crítica ya está siendo explotada para obtener acceso remoto. CVE-2026-9586 permite #SQLInjection sin autenticación. 🔗 https://t.co/ONZCzwskNd 🧵 Hilo #CyberSecurity 👇

    @totalcybersec

    2 Sept 2026

    230 Impressions

    2 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586): A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should… https://t.co/z04LRXuLcG htt

    @shah_sheikh

    2 Sept 2026

    63 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 CVE-2026-9586 - critical 🚨 Sangoma Switchvox &lt; 8.4.0.2 - Unauthenticated SQL Injection &gt; Sangoma Switchvox before version 8.4.0.2 contains an unauthenticated SQL injection vu... 👾 https://t.co/OOtGVzrHIC @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    2 Sept 2026

    472 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations