Active SQL injection in Sangoma Switchvox exploited
🔒 Horizon3 researchers report active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Switchvox’s /pa endpoint that can lead to remote code execution. The issue was one of 12 flaws disclosed to Sangoma and patched in Switchvox 8.4.0.2 on July 14. Attackers have attempted to establish reverse shells and exfiltrate process data from internet-exposed systems, prompting urgent upgrade and compromise checks.
