V-Help
← All news
Security

Hackers Exploit Sangoma Switchvox Flaw to Deploy Backdoors

Hackers Exploit Sangoma Switchvox Flaw to Deploy Backdoors

Photo: BleepingComputer

Quick answer

Cybercriminals are actively exploiting the critical CVE-2026-9586 SQL injection flaw in Sangoma Switchvox VoIP platform to achieve remote code execution and deploy reverse shells.

Cybercriminals are actively exploiting a critical vulnerability in Sangoma Switchvox, a corporate VoIP platform, enabling remote arbitrary code execution. Tracked as CVE-2026-9586, this unauthenticated SQL injection flaw targets the /pa endpoint, which processes XML messages with critical parameters.

According to Horizon3 researchers, attackers are leveraging the flaw to inject malicious code via specially crafted requests. In late August, mass attacks were detected originating from a single IP address (176.65.148.184), with attempts to deploy reverse shells on vulnerable systems. The attackers collected data on running processes and transmitted it to a remote server in encrypted form.

Sangoma patched the vulnerability in Switchvox version 8.4.0.2, released on July 14. However, Shodan data reveals approximately 4,000 vulnerable devices remain exposed online, predominantly in the U.S. Administrators are advised to urgently update the software and inspect systems for compromise indicators, including suspicious log entries and network connections to the known attacker IP.

Common questions

What is CVE-2026-9586?
A critical SQL injection vulnerability in Sangoma Switchvox that enables attackers to execute arbitrary code on vulnerable systems without authentication. The flaw affects the HTTP endpoint /pa.
How to protect against Switchvox attacks?
Update the system to version 8.4.0.2 or later. Check logs for suspicious entries and network connections to the attacker's IP address (176.65.148.184).
How many devices are vulnerable to this attack?
Shodan data indicates approximately 4,000 exposed Sangoma Switchvox devices, primarily in the U.S., most of which have already been targeted or remain at risk.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer