Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sangoma Switchvox unauthenticated SQL injection SQL injection flaw (CVE-2026-9586)

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-9586 is being actively exploited in Sangoma Switchvox, exposing internet-facing VoIP systems to remote code execution through an unauthenticated SQL injection flaw. Researchers say most exposed systems have already been targeted or will be soon, and honeypots saw repeated attempts from 176.65.148.184 on August 30. Sangoma fixed the issue in Switchvox 8.4.0.2, and administrators are urged to upgrade and review logs for compromise indicators.

Related Happenings

Sangoma Switchvox active exploitation wave (CVE-2026-9586)

Exploitation Wave
H score41 First: 03.09.2026 00:00 Last: 03.09.2026 00:00 Sources 1

How related: On August 30, Horizon3’s honeypots observed active exploitation on multiple systems in rapid succession from a single source IP address (176.65.148.184), with the attacker attempting to establish a reverse shell.

About this happening: CVE-2026-9586 is being exploited in a broad wave against internet-exposed Sangoma Switchvox systems, with repeated attempts and reverse-shell activity signaling immediate...

HPE OneView RondoDox exploitation wave (CVE-2025-37164)

Exploitation Wave
H score59 First: 16.01.2026 11:15 Last: 16.01.2026 11:15 Sources 1

About this happening: RondoDox has driven a large-scale exploitation wave against HPE OneView by targeting CVE-2025-37164, with activity escalating into automated attacks that creat...

Timeline

  1. 03.09.2026 00:00 1 articles · 2h ago

    Horizon3 reports 12 Switchvox flaws to Sangoma

    Technical Analysis Update

    Horizon3 discovered 12 flaws in Sangoma Switchvox and reported them to Sangoma on April 10, with CVE-2026-9586 identified as the most serious issue in the set.

    Show sources
  2. 03.09.2026 00:00 2 articles · 2h ago

    Horizon3 honeypots observe reverse-shell exploitation from 176.65.148.184

    Exploitation Observed

    On August 30, Horizon3 honeypots saw active exploitation of CVE-2026-9586 on multiple Switchvox systems in rapid succession from 176.65.148.184, and the attacker attempted to establish a reverse shell.

    Show sources
  3. 03.09.2026 00:00 1 articles · 2h ago

    Horizon3 says most internet-exposed Switchvox systems have already been targeted

    Initial Disclosure

    Horizon3 says attackers are actively exploiting CVE-2026-9586 in Sangoma Switchvox, warns that most internet-exposed Switchvox instances will be or have already been targeted, and recommends upgrading to Switchvox version 8.4.0.2 or later while checking /var/log/switchvox/db-quirks.log and connections to port 39323 for signs of compromise.

    Show sources