www.securityweek.com 9/4/2026, 1:58:36 PM · external

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Sangoma Switchvox Vulnerabilities Exploited in the Wild
CyberSIXT Evidence Panel

A critical-severity vulnerability (CVE-2026-9586) in Sangoma Switchvox, an enterprise VoIP solution, has been exploited by threat actors, allowing unauthenticated SQL injection for arbitrary code execution. This flaw, which scores 9.3 on the CVSS scale, can lead to remote exploitation through crafted XML requests without proper sanitization. Horizon3 reported the real-world exploitation and provided indicators of compromise.

CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog alongside six other critical issues, urging federal agencies to patch them promptly. Other vulnerabilities mentioned include CVE-2026-48710, CVE-2026-49869, and CVE-2026-59822, with specific patching timelines recommended.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline