Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability in Sangoma Switchvox Exploited

Critical Vulnerability in Sangoma Switchvox Exploited

Posted on September 4, 2026 By CWS

Cybersecurity experts have raised alarms over the active exploitation of a significant vulnerability within Sangoma Switchvox, a leading enterprise VoIP telephony management solution. Both Horizon3 and the Cybersecurity and Infrastructure Security Agency (CISA) have issued warnings about this critical flaw.

Details of the Exploit

The vulnerability, identified as CVE-2026-9586, carries a severe CVSS score of 9.3 and is categorized as an unauthenticated SQL injection issue. This flaw allows remote attackers to execute arbitrary code by exploiting weaknesses in the XML content processing endpoint, which fails to properly sanitize or parameterize the user-controlled PhoneIP value in PostgreSQL queries.

The National Institute of Standards and Technology (NIST) has highlighted the risk, stating that attackers can execute arbitrary SQL commands, perform database operations, and even achieve remote code execution through a single crafted request.

Recent Developments and Warnings

Horizon3 recently announced that threat actors have begun targeting CVE-2026-9586, sharing indicators of compromise (IoCs) to aid organizations in detecting potential breaches. In response, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion underscores the urgency for enterprises to address the security flaw.

Alongside CVE-2026-9586, CISA’s latest KEV update includes six other vulnerabilities, such as issues affecting JFrog Artifactory and SonicWall SMA1000, highlighting the ongoing threat landscape.

Additional Vulnerabilities and Mitigation

Among the newly added vulnerabilities is CVE-2026-48710, an HTTP request/response smuggling issue in the Starlette framework, which has been exploited since May. Another is CVE-2026-49869, a command injection flaw in the Kestra platform, flagged by Microsoft as exploited.

Finally, CVE-2026-59822, an authentication bypass issue in LiteLLM, has also been recognized for active exploitation. CISA advises federal agencies to patch these vulnerabilities swiftly, with a three-day deadline for most, while the Kestra and Starlette issues have a two-week window as per BOD 26-04 guidelines.

Organizations are urged to prioritize patching these vulnerabilities promptly to safeguard their systems from potential attacks and minimize the risk of unauthorized access and data breaches.

Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Related: Exploit Published for Fresh Cleo Harmony Vulnerability

Related: Hackers Start Exploiting Critical Langflow Vulnerability

Security Week News Tags:CISA, CVE, CVE-2026-9586, cyber threat, Cybersecurity, database security, Exploit, Horizon3, IoCs, remote code execution, Sangoma, security flaw, SQL injection, Switchvox, Vulnerability

Post navigation

Previous Post: Urgent Plex Media Server Update Fixes Security Issues
Next Post: TP-Link Archer Router Vulnerabilities Enable Remote Code Execution

Related Posts

How Software Development Teams Can Securely and Ethically Deploy AI Tools How Software Development Teams Can Securely and Ethically Deploy AI Tools Security Week News
Masimo Manufacturing Facilities Hit by Cyberattack Masimo Manufacturing Facilities Hit by Cyberattack Security Week News
Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Security Week News
Ukrainian Man Admits Guilt in US for Conti Ransomware Ukrainian Man Admits Guilt in US for Conti Ransomware Security Week News
Hackers Exploit Ninja Forms Vulnerability on WordPress Hackers Exploit Ninja Forms Vulnerability on WordPress Security Week News
Google Addresses Latest Chrome Zero-Day Vulnerability Google Addresses Latest Chrome Zero-Day Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark