bleeping-computer · Crawled Sep 3, 2026

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

1 IoCs
Read original article ↗

AI Summary

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform, to achieve remote code execution. The flaw exists in the /pa HTTP endpoint, which processes XML messages and improperly concatenates user-controlled input into SQL queries. Exploitation has been observed in the wild, with attackers attempting to deploy reverse shells and exfiltrate system information. Horizon3 observed multiple exploit attempts originating from a single IP address, indicating widespread targeting of internet-exposed Switchvox systems.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
IP 176[.]65[.]148[.]184 Details →