#8
The Hacker News
general
September 02, 2026 at 07:08 UTC
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
By [email protected] (The Hacker News)
AI Summary
CVE-2026-9586, a CVSS 9.3 unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 (build 104997), is being actively exploited to deploy reverse shells without credentials on enterprise VoIP infrastructure. The vulnerability allows full remote code execution on affected systems, which are commonly deployed for PBX functions in SMB environments. Organizations running Switchvox should apply available patches immediately and audit for indicators of reverse shell activity.
Relevance score: 81.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →