Sangoma Switchvox active exploitation wave (CVE-2026-9586)
Exploitation Wave
Summary
Hide ▲
Show ▼
CVE-2026-9586 is being exploited in a broad wave against internet-exposed Sangoma Switchvox systems, with repeated attempts and reverse-shell activity signaling immediate compromise risk for exposed deployments.
Related Happenings
Sangoma Switchvox unauthenticated SQL injection SQL injection flaw (CVE-2026-9586)
Vulnerability
H score41
First: 03.09.2026 00:00
Last: 03.09.2026 00:00
Sources 1
How related:
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
About this happening:
CVE-2026-9586 is being actively exploited in Sangoma Switchvox, exposing internet-facing VoIP systems to remote code execution through an unauthenticated SQL inj...
Sangoma Switchvox unauthenticated SQL injection SQL injection flaw (CVE-2026-9586)
VulnerabilityHow related: Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
About this happening: CVE-2026-9586 is being actively exploited in Sangoma Switchvox, exposing internet-facing VoIP systems to remote code execution through an unauthenticated SQL inj...
HPE OneView RondoDox exploitation wave (CVE-2025-37164)
Exploitation Wave
H score59
First: 16.01.2026 11:15
Last: 16.01.2026 11:15
Sources 1
About this happening:
RondoDox has driven a large-scale exploitation wave against HPE OneView by targeting CVE-2025-37164, with activity escalating into automated attacks that creat...
HPE OneView RondoDox exploitation wave (CVE-2025-37164)
Exploitation WaveAbout this happening: RondoDox has driven a large-scale exploitation wave against HPE OneView by targeting CVE-2025-37164, with activity escalating into automated attacks that creat...
Timeline
-
03.09.2026 00:00 1 articles · 2h ago
Horizon3 reports Switchvox flaws to Sangoma
Initial DisclosureHorizon3 reported 12 Switchvox flaws, including CVE-2026-9586, to Sangoma on April 10 after finding an unauthenticated SQL injection in the /pa HTTP endpoint that could lead to remote code execution.
Show sources
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — www.bleepingcomputer.com — 03.09.2026 00:00
-
03.09.2026 00:00 1 articles · 2h ago
Sangoma releases Switchvox 8.4.0.2
Mitigation Patch UpdateSangoma released Switchvox version 8.4.0.2 on July 14 to fix the 12 flaws, including CVE-2026-9586 in the /pa HTTP endpoint.
Show sources
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — www.bleepingcomputer.com — 03.09.2026 00:00
-
03.09.2026 00:00 2 articles · 2h ago
Honeypots observe active Switchvox exploitation
Exploitation ObservedHorizon3 honeypots observed active exploitation of CVE-2026-9586 against multiple internet-exposed Switchvox systems on August 30, and the attacker from 176.65.148.184 attempted to establish a reverse shell after executing an initial payload.
Show sources
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — www.bleepingcomputer.com — 03.09.2026 00:00
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — www.bleepingcomputer.com — 03.09.2026 00:00
-
03.09.2026 00:00 1 articles · 2h ago
Horizon3 warns most exposed Switchvox systems are likely targeted
Campaign Scope UpdateHorizon3 warned that most internet-exposed Switchvox systems have either already been targeted or will be soon, citing rapid exploit attempts from a single source IP and Shodan exposure estimates of approximately 4,000 devices, mostly in the United States.
Show sources
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — www.bleepingcomputer.com — 03.09.2026 00:00