news.mlab.sh
Back to the feed
vulnerability

Sangoma Switchvox Vulnerabilities Exploited in the Wild

CriticalCVSS 10.0
Summary

A critical SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox is being actively exploited in the wild, allowing attackers to execute arbitrary code and access sensitive data. The US Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, alongside several others, urging agencies to address the issues promptly.

A critical SQL injection vulnerability, tracked as CVE-2026-9586, has been identified in Sangoma Switchvox, a popular enterprise VoIP telephony management solution. This vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database. The issue stems from a lack of sanitization or parameterization when concatenating user-controlled PhoneIP values into PostgreSQL queries. The NIST advisory highlights that a single crafted request can lead to database operations and remote code execution. Cybersecurity firm Horizon3 warned on Tuesday that threat actors had begun exploiting this vulnerability in the wild, and they have shared indicators of compromise (IoCs) to assist organizations in identifying potential intrusions. The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, alongside other critical flaws, including CVE-2026-48710 (HTTP request/response smuggling in Starlette) and CVE-2026-49869 (command injection in Kestra). CISA is requesting that federal agencies patch these vulnerabilities within a timeframe of two to three weeks, depending on the specific issue. The vulnerability was disclosed in June and flagged as exploited by Microsoft last week. The vulnerability is part of a broader effort by CISA to address known exploited vulnerabilities and ensure the security of federal systems.

Read the full article at SecurityWeek