preloader

· · digital-security cve vulnerability-management infrastructure patch-management europe incident-response

Your Office Phone System Just Became a Way In. A SQL Injection Bug in Sangoma Switchvox Is Being Exploited Now

Source: Help Net Security

Phone systems rarely get the same security attention as web applications, which is exactly why attackers keep finding a way in through them.

An unauthenticated SQL injection with a straight line to RCE

CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox, a VoIP business phone platform, reachable through the product’s /pa HTTP endpoint. Rated 9.3, the flaw affects Switchvox SMB Edition 8.3 build 104997 and earlier, and it does not stop at data exposure: chained correctly, the injection leads to remote code execution on the server.

Attackers moved within days of disclosure

Researchers at Horizon3.ai observed valid exploitation attempts against internet-exposed Switchvox devices starting August 30, with attackers deploying reverse shells to get interactive command-line access to compromised systems. Some compromised hosts were then used to download second-stage payloads, including what researchers identified as cryptomining malware. CISA added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog on September 2, confirming the exploitation is real and ongoing, not theoretical.

The patch has existed since mid-July

Sangoma fixed the vulnerability in Switchvox 8.4.0.2, released July 14. Every instance still running the vulnerable version and reachable from the internet by the time exploitation began in late August had roughly six weeks of public advisory time to get patched. That gap between “a fix exists” and “the fix gets applied” is where most successful exploitation actually happens, and phone systems tend to sit lower on the patching priority list than the servers everyone remembers to watch.

Why VoIP infrastructure deserves the same scrutiny as your web stack

A compromised PBX is not a minor inconvenience. It typically has access to call routing, voicemail, directory data and often sits on the same internal network segment as other business-critical systems, which makes it a useful pivot point once an attacker has a shell. Reverse shells and cryptominers are also frequently just the first payload; the access itself is what has lasting value.

If your organisation runs VoIP, PBX or any communications infrastructure you have not reviewed recently, now is the time to check the version, confirm it is not needlessly exposed to the internet, and look for signs of the reverse shell and cryptominer activity researchers have already documented.

If you want a proper audit of your infrastructure, including the systems that do not usually make it onto a patch management dashboard, contact Excello Digital. We help European organisations find the blind spots before attackers do.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!