Sangoma Switchvox vulnerabilities are being exploited in the wild

Sangoma Switchvox vulnerabilities are being exploited in the wild

Threat actors have exploited a critical vulnerability in the enterprise VoIP phone management solution Sangoma Switchvox, Horizon3 and CISA.

Tracked as CVE-2026-9586 (CVSS score of 9.3) and described as an unauthenticated SQL injection issue, the security flaw can be exploited remotely for arbitrary code execution.

It resides in an endpoint that processes XML content that has not undergone sanitization or parameterization when concatenating the user-controlled PhoneIP value in PostgreSQL queries.

“An unauthenticated remote attacker can execute arbitrary SQL statements against the back-end PostgreSQL database, including database operations and remote code execution, using a single crafted request,” according to a NIST advisory reads.

On Tuesday, cybersecurity company Horizon3 warned that threat actors had begun exploiting CVE-2026-9586 in the wild and were sharing Indicators of Compromise (IoCs) to help organizations detect potential breaches.

On Wednesday, the US cybersecurity agency CISA added the vulnerability to its known exploited vulnerabilities (KEV) catalog along with six other issues, including the JFrog Artifactory bug and two SonicWall SMA1000 zero-days that were recently reported as exploited.

Advertising. Scroll to continue reading.

The fifth vulnerability added to CISA KEV is CVE-2026-48710, an HTTP request/response smuggling flaw in the lightweight ASGI framework Starlette that was publicly disclosed in May. Hackers have been exploiting Horizon3 since May said Beginning of June.

Next up is CVE-2026-49869, a fatal command injection flaw in the open source orchestration platform Kestra that was disclosed in June and marked as exploited Microsoft last week.

The latest vulnerability added to CISA’s KEV list on Wednesday is CVE-2026-59822, a high-level authentication bypass in LiteLLM. Last week, Wiz said Its honeypots intercepted exploit attempts targeting this flaw.

CISA requires federal agencies to remediate these vulnerabilities within three days, with the exception of the Kestra and Starlette vulnerabilities, which should be remedied within two weeks according to BOD 26-04 recommendations.

Related: Over 3 million WordPress sites affected by migration plugin vulnerability

Related: Cisco warns of unpatched email vulnerabilities and fixes critical switch vulnerabilities

Related: Exploit for Fresh Cleo Harmony vulnerability released

Related: Hackers begin exploiting critical Langflow vulnerability

Leave a Reply

Your email address will not be published. Required fields are marked *