Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Switchvox Vulnerability Exploited for Remote Code Execution

Critical Switchvox Vulnerability Exploited for Remote Code Execution

Posted on September 2, 2026 By CWS

Cybersecurity experts are raising alarms over a critical security flaw in the Sangoma Switchvox VoIP platform. This vulnerability, identified as CVE-2026-9586, is being actively exploited by threat actors to execute remote code without requiring any authentication.

Understanding the Sangoma Switchvox Flaw

The vulnerability, which has been assigned a CVSS score of 9.3, is a severe unauthenticated SQL injection flaw present in Sangoma Switchvox SMB Edition 8.3 (104997). This security gap allows malicious actors to execute arbitrary code remotely with the privileges of a PostgreSQL superuser, bypassing the need for credentials. Sangoma addressed this issue with the release of patches in version 8.4.0.2 on July 14, 2026.

According to CVE.org, the flaw stems from the way the /pa endpoint processes XML input, directly inserting user-supplied PhoneIP data into PostgreSQL queries without proper sanitization. This oversight enables attackers to craft requests that can compromise the backend database and execute remote commands.

Exploitation and Impact

Horizon3.ai has reported that CVE-2026-9586 is one of 12 vulnerabilities reported to Sangoma in April 2026. Exploitation attempts were first observed on August 30, 2026, with approximately 4,000 vulnerable instances, predominantly in the U.S., exposed to the internet.

Independent discovery and reporting of the same flaw were made by Security Risk Advisors (SRA) Labs in May. They demonstrated that unauthenticated attackers could manipulate database operations, extract data, modify records, and elevate privileges to Switchvox web administrators. Moreover, attackers could execute arbitrary code, including reverse shells.

Indicators of Compromise and Mitigation

Attackers have been observed deploying reverse shells on compromised systems and using Base64-encoded commands to investigate running processes. Notably, devices with SSH access show SQL injection payload traces in ‘/var/log/switchvox/db-quirks.log’, and the attacking IP address ‘176.65.148[.]184’ has been flagged for malicious activities.

Zach Hanley, a security researcher, warns of widespread targeting of internet-exposed Switchvox instances, driven by rapid exploit attempts from a single source IP across multiple honeypots.

The prompt application of patches provided by Sangoma is crucial to mitigate these threats. Organizations using the affected versions of Switchvox should update immediately to protect against potential breaches.

The Hacker News Tags:CVE-2026-9586, Cybersecurity, Honeypots, network security, Patches, remote code execution, Sangoma, SQL injection, Switchvox, Threat Actors, VoIP, Vulnerability

Post navigation

Previous Post: Google Debuts Gemini 3.8 Flash Cyber for Security Patching
Next Post: Firefox iOS Introduces Built-In Ad Blocker Feature

Related Posts

N-central Hotfix 2 Released Amid Security Concerns N-central Hotfix 2 Released Amid Security Concerns The Hacker News
Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE The Hacker News
Amazon Kiro Vulnerability Risks Data Exposure Amazon Kiro Vulnerability Risks Data Exposure The Hacker News
TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution The Hacker News
Critical MOVEit Automation Flaw Patches Released by Progress Critical MOVEit Automation Flaw Patches Released by Progress The Hacker News
New ClickFix Variant Exploits Network Drives New ClickFix Variant Exploits Network Drives The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark