Attackers Exploit Sangoma Switchvox Bug to Plant Reverse Shells
Hackers are exploiting a newly disclosed vulnerability, tracked as CVE-2026-9586, in Sangoma's Switchvox VoIP phone system. The flaw is an unauthenticated SQL injection bug, meaning attackers don't need any login credentials to abuse it. By sending crafted requests to vulnerable instances, attackers can manipulate the underlying database and ultimately achieve remote code execution.
Once inside, threat actors have been observed deploying reverse shells, giving them persistent remote access to compromised systems. Because Switchvox handles business phone and communications infrastructure, successful exploitation can expose call data, internal network access, and a foothold for further lateral movement.
Sangoma has released patches addressing the issue, and organizations running Switchvox are urged to update immediately and check logs for signs of compromise.