Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

An unauthenticated SQL injection in Sangoma's Switchvox VoIP platform (CVE-2026-9586) is being exploited in the wild to deploy reverse shells — a reminder that telephony infrastructure is often an unmonitored entry point.

Summary written by editorial AI · Source link below

Filed by BleepingComputer1 min readCVE-2026-9586Read at source ↗
CVSS9.8criticalCVE-2026-9586

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

Editorial Analysis

Why it matters

VoIP platforms are frequently treated as appliances and excluded from regular patching cycles, making them attractive targets for attackers seeking unmonitored network footholds.

What to do

Identify any Sangoma Switchvox deployments, apply available patches immediately, and segment VoIP infrastructure from critical network zones.

Board brief

Attackers are exploiting a VoIP platform vulnerability to gain network access — verify your telephony systems are patched and segmented.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at BleepingComputer

External link — opens at BleepingComputer in a new tab.

§
Continue with

More from the Vulnerabilities Desk