🔘 Vulnerability(cybersecuritynews.com): Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks
✉ 03.09.2026 13:59:24 Abinaya
💻 A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics.
The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on vulnerable systems without needing valid credentials.
Horizon3.ai researchers observed valid exploitation attempts against internet-exposed Switchvox devices on August 30, 2026, with attackers attempting to deploy reverse shells for remote command-line access to compromised VoIP servers.
CVE-2026-9586 is an unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition 8.3, build 104997, and earlier releases. The issue has a CVSS severity score of 9.3 and can lead to remote code execution.
The vulnerable component is an unauthenticated HTTP endpoint, /pa, that processes XML messages for supported IP phones. These messages can be used to notify phone systems about events such as incoming and outgoing calls.
Hackers Exploiting Sangoma Switchvox VoIP RCE Flaw
Horizon3 researchers found that Switchvox extracts the PhoneIP value from an XML request and directly adds it to a PostgreSQL database query.
The application does not properly sanitize or parameterize the user-controlled input. This allows a remote attacker to inject malicious SQL commands through a specially crafted request.
Because the database query is executed with elevated PostgreSQL permissions, an attacker could run operating system commands on the Switchvox server.
This could allow them to access database contents, alter user data, create or elevate administrator accounts, steal authentication material, and establish persistent remote access.
Same attacker IP hits multiple honeypots. (Source: Horizon)
Horizon3 and Defused Cyber deployed internet-facing honeypots to monitor for exploitation attempts. On August 30, researchers detected attacks from the IP address 176.65.148.184 across multiple honeypots in quick succession.
The observed activity included an attempt to launch a reverse shell using Netcat. Attackers then used a Base64-encoded command to collect information on active processes running on the vulnerable Switchvox appliance.
The results were prepared for transmission to an attacker-controlled server, suggesting that the attackers were conducting post-exploitation reconnaissance after gaining access.
Horizon3 warned that the speed and scale of the attempts indicate that internet-exposed Switchvox systems are likely being broadly scanned and ...
#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/hackers-exploiting-sangoma-switchvox-voip-rce-flaw/
read it on CSN:
https://csn.net4me.net/cyber_security_27916.html