Cybersecurity experts have raised alarms over the active exploitation of a significant vulnerability within Sangoma Switchvox, a leading enterprise VoIP telephony management solution. Both Horizon3 and the Cybersecurity and Infrastructure Security Agency (CISA) have issued warnings about this critical flaw.
Details of the Exploit
The vulnerability, identified as CVE-2026-9586, carries a severe CVSS score of 9.3 and is categorized as an unauthenticated SQL injection issue. This flaw allows remote attackers to execute arbitrary code by exploiting weaknesses in the XML content processing endpoint, which fails to properly sanitize or parameterize the user-controlled PhoneIP value in PostgreSQL queries.
The National Institute of Standards and Technology (NIST) has highlighted the risk, stating that attackers can execute arbitrary SQL commands, perform database operations, and even achieve remote code execution through a single crafted request.
Recent Developments and Warnings
Horizon3 recently announced that threat actors have begun targeting CVE-2026-9586, sharing indicators of compromise (IoCs) to aid organizations in detecting potential breaches. In response, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion underscores the urgency for enterprises to address the security flaw.
Alongside CVE-2026-9586, CISA’s latest KEV update includes six other vulnerabilities, such as issues affecting JFrog Artifactory and SonicWall SMA1000, highlighting the ongoing threat landscape.
Additional Vulnerabilities and Mitigation
Among the newly added vulnerabilities is CVE-2026-48710, an HTTP request/response smuggling issue in the Starlette framework, which has been exploited since May. Another is CVE-2026-49869, a command injection flaw in the Kestra platform, flagged by Microsoft as exploited.
Finally, CVE-2026-59822, an authentication bypass issue in LiteLLM, has also been recognized for active exploitation. CISA advises federal agencies to patch these vulnerabilities swiftly, with a three-day deadline for most, while the Kestra and Starlette issues have a two-week window as per BOD 26-04 guidelines.
Organizations are urged to prioritize patching these vulnerabilities promptly to safeguard their systems from potential attacks and minimize the risk of unauthorized access and data breaches.
Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Related: Exploit Published for Fresh Cleo Harmony Vulnerability
Related: Hackers Start Exploiting Critical Langflow Vulnerability
