🛑 Attackers are exploiting Switchvox without credentials to deploy reverse shells.
CVE-2026-9586 is a critical SQL injection in the /pa endpoint. About 4,000 instances are exposed online, and Sangoma has released a patch.
Inside the exploit: https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html

September 2, 2026 3.3K 15