Critical Vulnerability Exploited in Sangoma Switchvox VoIP Solution
A critical-severity vulnerability is being actively exploited by threat actors in the enterprise Voice over Internet Protocol (VoIP) telephony management solution Sangoma Switchvox. The flaw, tracked as CVE-2026-9586 with a CVSS score of 9.3, allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request.
The vulnerability resides in an endpoint that processes XML content, which fails to sanitize or parameterize user-controlled input when concatenating it into PostgreSQL queries. This enables attackers to bypass authentication and inject malicious SQL code to manipulate the database or execute unauthorized commands on the system. Horizon3, a cybersecurity firm, has warned of exploitation attempts in the wild and shared indicators of compromise (IoCs) to aid organizations in detecting potential intrusions.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog along with six other recently flagged vulnerabilities. These include a critical-severity bug in the JFrog Artifactory software, two zero-day flaws in SonicWall’s SMA1000, an HTTP request/response smuggling vulnerability in the Starlette framework, and a command injection defect in Kestra.
CISA is urging federal agencies to patch these vulnerabilities within three days, except for the Kestra and Starlette flaws, which should be patched within two weeks. This emphasizes the importance of timely patches and updates to prevent exploitation by malicious actors.
The Sangoma Switchvox vulnerability demonstrates how easily attackers can leverage critical-severity bugs to gain unauthorized access to sensitive systems and data. It is essential for organizations using this solution to apply patches as soon as possible and implement robust security measures to mitigate potential risks.
For readers who use or manage VoIP solutions, it’s crucial to stay informed about known vulnerabilities and prioritize timely patching and updates. If you’re unsure whether your system is affected or need assistance with the patching process, consider consulting with a qualified cybersecurity professional to ensure your organization remains secure.
Source: SecurityWeek — 2026-09-04