Attackers are exploiting Switchvox without credentials to deploy… — The Hacker News — TG.ME

🛑 Attackers are exploiting Switchvox without credentials to deploy reverse shells.

CVE-2026-9586 is a critical SQL injection in the /pa endpoint. About 4,000 instances are exposed online, and Sangoma has released a patch.

Inside the exploit: https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
September 2, 2026 3.3K 15