Home / Sep 03, 2026 / Story
0
#8 The Hacker News general September 02, 2026 at 07:08 UTC

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

By [email protected] (The Hacker News)

AI Summary

CVE-2026-9586, a CVSS 9.3 unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 (build 104997), is being actively exploited to deploy reverse shells without credentials on enterprise VoIP infrastructure. The vulnerability allows full remote code execution on affected systems, which are commonly deployed for PBX functions in SMB environments. Organizations running Switchvox should apply available patches immediately and audit for indicators of reverse shell activity.

Relevance score: 81.0/100

# More from September 03