Apply Sangoma's released security updates and firmware patches immediately. Restrict network access to the Switchvox management interface to trusted networks only. Monitor logs for suspicious SQL injection attempts or unexpected reverse shell connections.
Quick answers
What is CVE-2026-9586?
Apply Sangoma's released security updates and firmware patches immediately. Restrict network access to the Switchvox management interface to trusted networks only. Monitor logs for suspicious SQL injection attempts or unexpected reverse shell connections.
How severe is CVE-2026-9586?
critical
Is CVE-2026-9586 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-9586 be mitigated?
Apply Sangoma's released security updates and firmware patches immediately. Restrict network access to the Switchvox management interface to trusted networks only. Monitor logs for suspicious SQL injection attempts or unexpected reverse shell connections.
CVSS
—
Vendor
Sangoma
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Switchvox
Mitigation
Apply Sangoma's released security updates and firmware patches immediately. Restrict network access to the Switchvox management interface to trusted networks only. Monitor logs for suspicious SQL injection attempts or unexpected reverse shell connections.
The Cybersecurity and Infrastructure Security Agency (CISA) has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The additions span multiple vendors and technologies, including Sangoma Switchvox, Kludex Starlette, Kestra OSS, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. CISA emphasized that these flaws represent frequent attack vectors for malicious actors targeting federal and critical infrastructure systems.
Threat actors are exploiting a severe unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 to achieve remote code execution and deploy reverse shells without requiring credentials. The flaw, tracked as CVE-2026-9586 with a CVSS score of 9.3, affects enterprise VoIP infrastructure globally. Sangoma has released security updates; users are advised to apply patches immediately to mitigate active exploitation risk.
Security researchers and BleepingComputer report that threat actors are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform. The flaw enables remote code execution, allowing attackers to deploy reverse shells and potentially achieve full system compromise. Sangoma has released security updates to address the vulnerability, and administrators are urged to apply them immediately.