By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit Sangoma Switchvox SQL Injection Flaw
Threat actors are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability affecting the Sangoma Switchvox Voice over IP (VoIP) phone system. This vulnerability, identified and tracked by security researchers, allows attackers to execute arbitrary SQL commands on the underlying database, which can then be leveraged to achieve remote code execution (RCE) on the targeted Switchvox appliance. The exploitation chain begins with the injection of malicious SQL queries through an unauthenticated interface, bypassing any necessary login credentials. Once the SQL injection is successful, attackers can manipulate the database to either extract sensitive information or, more critically, to plant malicious code that the system will then execute. This allows for complete compromise of the Switchvox server, enabling attackers to establish persistent access, deploy further malware, or use the compromised system as a pivot point into a broader network. The Sangoma Switchvox platform is a widely used business phone system that integrates voice, video, and messaging functionalities, making a compromise of its core system a significant security risk for organizations relying on it for their communication infrastructure. The ability to execute remote code means attackers could potentially eavesdrop on calls, redirect calls to malicious numbers, or disable communication services entirely. Security advisories have been issued by multiple cybersecurity firms, detailing the technical aspects of the exploit and urging administrators to apply patches or implement mitigation strategies. The specific nature of the vulnerability, being an SQL injection, suggests that the application's backend handling of user-supplied data is not adequately sanitizing or validating input before it is processed by the database. This type of vulnerability is particularly dangerous because it can be exploited without prior authentication, meaning any internet-facing Switchvox instance is potentially vulnerable. Organizations using Sangoma Switchvox are advised to immediately review their security configurations, ensure their systems are updated to the latest available firmware, and monitor network traffic for any signs of suspicious activity indicative of exploitation. The exploitation of such vulnerabilities underscores the ongoing threat landscape for business communication systems, where a single flaw can have far-reaching consequences for an organization's operational continuity and data security. The active exploitation indicates that attackers have developed reliable methods to weaponize this specific CVE, moving beyond theoretical proof-of-concept to real-world attacks. This situation highlights the importance of timely patching and robust security practices for all critical business infrastructure, especially those handling sensitive communication data and providing essential operational services.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.