THREAT OPS › CVEs › CVE-2026-9586
CVE-2026-9586 — Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Vulnerability details
- Affected productsSwitchvox
- KEV remediation due2026-09-05
Related reporting
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shellsbleepingcomputer
- CISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-9586 — Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerabilitycisa_kev
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentialsthehackernews
- CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerabilityhorizon3
- Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586horizon3