bleeping-computer · Crawled Sep 3, 2026
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
1 IoCs
Read original article ↗
AI Summary
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform, to achieve remote code execution. The flaw exists in the /pa HTTP endpoint, which processes XML messages and improperly concatenates user-controlled input into SQL queries. Exploitation has been observed in the wild, with attackers attempting to deploy reverse shells and exfiltrate system information. Horizon3 observed multiple exploit attempts originating from a single IP address, indicating widespread targeting of internet-exposed Switchvox systems.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 176[.]65[.]148[.]184 | Details → |