CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5529

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are actively exploiting CVE-2026-9586, a critical SQL injection flaw in Sangoma Switchvox that enables unauthenticated remote code execution on the enterprise VoIP platform. The vulnerability affects Switchvox SMB Edition 8.3 and carries a CVSS score of 9.3.

Why it matters: Organizations running Sangoma Switchvox SMB Edition 8.3 face immediate risk of compromise without requiring attacker credentials; patching or isolating affected instances should be a priority.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are actively exploiting CVE-2026-9586, a critical SQL injection flaw in Sangoma Switchvox that enables unauthenticated remote code execution on the enterprise VoIP platform. The vulnerability affects Switchvox SMB Edition 8.3 and carries a CVSS score of 9.3.

Why it matters: Organizations running Sangoma Switchvox SMB Edition 8.3 face immediate risk of compromise without requiring attacker credentials; patching or isolating affected instances should be a priority.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors actively exploit CVE-2026-9586, a critical unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 that enables remote code execution without credentials. The vulnerability carries a CVSS score of 9.3 and is tracked on the Known Exploited Vulnerabilities (KEV) catalog. Attackers leverage this weakness to deploy reverse shells in enterprise VoIP environments.

Why it matters: Organizations running Sangoma Switchvox SMB Edition 8.3 face immediate risk of unauthenticated compromise; patching or disabling the affected system should be prioritized today given active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors actively exploit CVE-2026-9586, a critical unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 that enables remote code execution without credentials. The vulnerability carries a CVSS score of 9.3 and is tracked on the Known Exploited Vulnerabilities (KEV) catalog. Attackers leverage this weakness to deploy reverse shells in enterprise VoIP environments.

Why it matters: Organizations running Sangoma Switchvox SMB Edition 8.3 face immediate risk of unauthenticated compromise; patching or disabling the affected system should be prioritized today given active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors actively exploit CVE-2026-9586, a critical unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 that enables remote code execution without credentials. The vulnerability carries a CVSS score of 9.3 and is tracked on the Known Exploited Vulnerabilities (KEV) catalog. Attackers leverage this weakness to deploy reverse shells in enterprise VoIP environments.

Why it matters: Organizations running Sangoma Switchvox SMB Edition 8.3 face immediate risk of unauthenticated compromise; patching or disabling the affected system should be prioritized today given active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary