Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sangoma Switchvox active exploitation wave (CVE-2026-9586)

Exploitation Wave
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-9586 is being exploited in a broad wave against internet-exposed Sangoma Switchvox systems, with repeated attempts and reverse-shell activity signaling immediate compromise risk for exposed deployments.

Related Happenings

Sangoma Switchvox unauthenticated SQL injection SQL injection flaw (CVE-2026-9586)

Vulnerability
H score41 First: 03.09.2026 00:00 Last: 03.09.2026 00:00 Sources 1

How related: Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.

About this happening: CVE-2026-9586 is being actively exploited in Sangoma Switchvox, exposing internet-facing VoIP systems to remote code execution through an unauthenticated SQL inj...

HPE OneView RondoDox exploitation wave (CVE-2025-37164)

Exploitation Wave
H score59 First: 16.01.2026 11:15 Last: 16.01.2026 11:15 Sources 1

About this happening: RondoDox has driven a large-scale exploitation wave against HPE OneView by targeting CVE-2025-37164, with activity escalating into automated attacks that creat...

Timeline

  1. 03.09.2026 00:00 1 articles · 2h ago

    Horizon3 reports Switchvox flaws to Sangoma

    Initial Disclosure

    Horizon3 reported 12 Switchvox flaws, including CVE-2026-9586, to Sangoma on April 10 after finding an unauthenticated SQL injection in the /pa HTTP endpoint that could lead to remote code execution.

    Show sources
  2. 03.09.2026 00:00 2 articles · 2h ago

    Honeypots observe active Switchvox exploitation

    Exploitation Observed

    Horizon3 honeypots observed active exploitation of CVE-2026-9586 against multiple internet-exposed Switchvox systems on August 30, and the attacker from 176.65.148.184 attempted to establish a reverse shell after executing an initial payload.

    Show sources
  3. 03.09.2026 00:00 1 articles · 2h ago

    Horizon3 warns most exposed Switchvox systems are likely targeted

    Campaign Scope Update

    Horizon3 warned that most internet-exposed Switchvox systems have either already been targeted or will be soon, citing rapid exploit attempts from a single source IP and Shodan exposure estimates of approximately 4,000 devices, mostly in the United States.

    Show sources