GKRootWire
Security 153 Million Driver's Licenses Reportedly Leaked in Massive BreachSecurity Palo Alto Networks Reportedly Pays $500M for AI IT Automation Startup ConsoleDev Tools Wasmi v2.0 Pushes WebAssembly Interpreters to New Speed LimitsDev Tools How to Reverse Engineer Unknown File Formats with ImHexDev Tools The Original Microsoft Source Code: Altair BASIC From 1975 ResurfacesSecurity Attackers Exploit Sangoma Switchvox Bug to Plant Reverse ShellsSecurity 153 Million Driver's Licenses Reportedly Leaked in Massive BreachSecurity Palo Alto Networks Reportedly Pays $500M for AI IT Automation Startup ConsoleDev Tools Wasmi v2.0 Pushes WebAssembly Interpreters to New Speed LimitsDev Tools How to Reverse Engineer Unknown File Formats with ImHexDev Tools The Original Microsoft Source Code: Altair BASIC From 1975 ResurfacesSecurity Attackers Exploit Sangoma Switchvox Bug to Plant Reverse Shells
Security

Attackers Exploit Sangoma Switchvox Bug to Plant Reverse Shells

An unauthenticated SQL injection flaw in the popular VoIP platform is being actively weaponized to gain remote code execution.

Hackers are exploiting a newly disclosed vulnerability, tracked as CVE-2026-9586, in Sangoma's Switchvox VoIP phone system. The flaw is an unauthenticated SQL injection bug, meaning attackers don't need any login credentials to abuse it. By sending crafted requests to vulnerable instances, attackers can manipulate the underlying database and ultimately achieve remote code execution.

Once inside, threat actors have been observed deploying reverse shells, giving them persistent remote access to compromised systems. Because Switchvox handles business phone and communications infrastructure, successful exploitation can expose call data, internal network access, and a foothold for further lateral movement.

Sangoma has released patches addressing the issue, and organizations running Switchvox are urged to update immediately and check logs for signs of compromise.

Why it matters: VoIP and unified communications platforms are often overlooked in patch management despite sitting on business networks with broad access, making them attractive targets for initial-access brokers. Unauthenticated SQLi-to-RCE chains are especially dangerous because they require zero credentials and are easy to automate at scale.

Sources: BleepingComputer