Critical Vulnerability in Sangoma Switchvox Exposes Enterprise VoIP Systems to Remote Attacks
A high-severity vulnerability in Sangoma Switchvox, a widely used enterprise VoIP telephony management solution, is being actively exploited by threat actors. The flaw, tracked as CVE-2026-9586, allows an unauthenticated attacker to execute arbitrary code on the affected system, highlighting the urgent need for patching.
Sangoma Switchvox is designed to manage and integrate voice-over-internet protocol (VoIP) systems in large organizations. However, a critical vulnerability in its XML processing endpoint has left these systems exposed to remote attacks. According to security researchers at Horizon3, the flaw can be exploited using a single crafted request that executes arbitrary SQL statements against the backend PostgreSQL database.
The vulnerability stems from the failure of Sangoma Switchvox to properly sanitize or parameterize user-controlled input when concatenating it into PostgreSQL queries. This weakness allows an attacker to bypass authentication and inject malicious code, potentially leading to database operations and remote code execution. Horizon3 has shared indicators of compromise (IoCs) with organizations to help identify potential intrusions.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the CVE-2026-9586 vulnerability to its Known Exploited Vulnerabilities catalog, along with six other issues that have been exploited in the wild. These include vulnerabilities in JFrog Artifactory, SonicWall SMA1000, Starlette, Kestra, and LiteLLM.
CISA is urging federal agencies to patch these vulnerabilities within a specified timeframe. For CVE-2026-9586, organizations should prioritize patching as soon as possible to prevent potential exploitation. This vulnerability serves as a stark reminder of the importance of regular security updates and vulnerability management.
In practical terms, IT administrators responsible for Sangoma Switchvox systems should take immediate action to:
* Check their system’s version against the affected range
* Review and apply available patches or workarounds
* Implement robust access controls and monitoring to detect potential intrusions
By staying vigilant and taking proactive measures, organizations can minimize the risk of exploitation and protect their sensitive data. As security threats continue to evolve, it is crucial for companies to prioritize patching and stay informed about emerging vulnerabilities.
Source: SecurityWeek — 2026-09-04