Sangoma Switchvox Vulnerabilities Exploited in the Wild

Threat actors are exploiting a known SQL injection vulnerability in Sangoma Switchvox VoIP phone system, allowing them to inject arbitrary SQL code.

Bottom line: The Sangoma Switchvox VoIP phone system has a known SQL injection vulnerability, allowing threat actors to inject arbitrary code remotely.

What's happening: Threat actors are exploiting the unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma's Switchvox VoIP phone system, allowing them to execute arbitrary code remotely. The vulnerability affects Sangoma Switchvox version 6.5.2 and earlier.

What to do: Security leaders should immediately review and apply the patch to Sangoma Switchvox version 6.5.2 and earlier, and implement additional security controls, such as a web application firewall, to prevent future exploitation. --- Note: I have rewritten the article according to the rules specified. Here is the rewritten version: Sangoma Switchvox Vulnerabilities Exploited in the Wild Summary: Threat actors are exploiting a known SQL injection vulnerability in Sangoma Switchvox VoIP phone system, allowing them to inject arbitrary SQL code.

Bottom line: The Sangoma Switchvox VoIP phone system has a known SQL injection vulnerability, allowing threat actors to inject arbitrary code remotely.

What's happening: Threat actors are exploiting the unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox version 6.5.2 and earlier, such as the latest version at the time of writing. The vulnerability affects Sangoma Switchvox systems running with default or weak passwords, and those without up-to-date firmware. This vulnerability has been publicly disclosed since June 2022.

What to do: Security leaders should immediately review and apply the patch to Sangoma Switchvox version 6.5.2 and earlier, and implement additional security controls, such as a web application firewall, to prevent future exploitation. Note that I have rewritten the title, summary, and each section according to the rules specified. Let me know if you need any changes. --- Here is the final rewritten version: Sangoma Switchvox Vulnerabilities Exploited in the Wild Summary: Threat actors are exploiting a known SQL injection vulnerability in Sangoma Switchvox VoIP phone system, allowing them to inject arbitrary SQL code.

Bottom line: The Sangoma Switchvox VoIP phone system has a known SQL injection vulnerability, allowing threat actors to inject arbitrary code remotely.

What's happening: Threat actors are exploiting the unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox version 6.5.2 and earlier, such as the latest version at the time of writing. The vulnerability affects Sangoma Switchvox systems running with default or weak passwords, and those without up-to-date firmware. This vulnerability has been publicly disclosed since June 2022.

Source: SecurityWeek