Phone systems rarely get the same security attention as web applications, which is exactly why attackers keep finding a way in through them.
An unauthenticated SQL injection with a straight line to RCE
CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox, a VoIP business phone platform, reachable through the product’s /pa HTTP endpoint. Rated 9.3, the flaw affects Switchvox SMB Edition 8.3 build 104997 and earlier, and it does not stop at data exposure: chained correctly, the injection leads to remote code execution on the server.
Attackers moved within days of disclosure
Researchers at Horizon3.ai observed valid exploitation attempts against internet-exposed Switchvox devices starting August 30, with attackers deploying reverse shells to get interactive command-line access to compromised systems. Some compromised hosts were then used to download second-stage payloads, including what researchers identified as cryptomining malware. CISA added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog on September 2, confirming the exploitation is real and ongoing, not theoretical.
The patch has existed since mid-July
Sangoma fixed the vulnerability in Switchvox 8.4.0.2, released July 14. Every instance still running the vulnerable version and reachable from the internet by the time exploitation began in late August had roughly six weeks of public advisory time to get patched. That gap between “a fix exists” and “the fix gets applied” is where most successful exploitation actually happens, and phone systems tend to sit lower on the patching priority list than the servers everyone remembers to watch.
Why VoIP infrastructure deserves the same scrutiny as your web stack
A compromised PBX is not a minor inconvenience. It typically has access to call routing, voicemail, directory data and often sits on the same internal network segment as other business-critical systems, which makes it a useful pivot point once an attacker has a shell. Reverse shells and cryptominers are also frequently just the first payload; the access itself is what has lasting value.
If your organisation runs VoIP, PBX or any communications infrastructure you have not reviewed recently, now is the time to check the version, confirm it is not needlessly exposed to the internet, and look for signs of the reverse shell and cryptominer activity researchers have already documented.
If you want a proper audit of your infrastructure, including the systems that do not usually make it onto a patch management dashboard, contact Excello Digital. We help European organisations find the blind spots before attackers do.
