Vulnerability
Published 2026-07-14
Verified 2026-09-19

Sangoma Switchvox unauthenticated SQLi to RCE exploited (CVE-2026-9586); CISA KEV

Horizon3 published on 1 September 2026 that Defused Cyber honeypots saw valid in-the-wild exploitation of CVE-2026-9586 on 30 August 2026 (attacker IP 176.65.148.184 in the published honeypot traffic). The flaw is an unauthenticated SQL injection in Sangoma Switchvox SMB Edition: the /pa PhoneAppsHandler.pm endpoint concatenates the PhoneIP field from an XML body into a PostgreSQL query, which Horizon3 says can be turned into remote code execution as the database superuser. Sangoma released Switchvox 8.4.0.2 on 14 July 2026. Horizon3 reported the issues in April; Security Risk Advisors independently reported them in May and published on 17 July. GitHub CVE advisory (17 July) rates it Critical 9.3. The CNA record cites Switchvox SMB Edition 8.3 (build 104997); Horizon3 notes Sangoma 8.4.0.2 release notes also mention 8.2.2.1 — upgrade to 8.4.0.2 rather than assuming an older build is safe. Horizon3 cites about 4,000 internet-exposed Switchvox devices on Shodan, mostly in the United States. CISA added CVE-2026-9586 to the KEV catalog on 2 September 2026. Restrict /pa to trusted phone networks until patched. IoC path if SSH is available: /var/log/switchvox/db-quirks.log.

Product
Sangoma Switchvox SMB Edition
Versions
Before 8.4.0.2 (CNA: 8.3/104997; vendor notes also mention 8.2.2.1)
CVSS
9.3 (Critical; GitHub advisory / CVSS 4.0 as reported by Horizon3)
Exploited in Australia?
unknown
Patch to
Switchvox 8.4.0.2 or later; restrict /pa to trusted phone networks

Primary: Sangoma Switchvox 8.4.0.2 release notes (14 Jul 2026) · Vendor: Sangoma (vendor) · CVE: CVE-2026-9586 · Horizon3 (1 Sep 2026; exploitation); CISA KEV 2 Sep

vulnerabilities network