Critical Sangoma Switchvox SQL injection under active exploit

Attackers exploit an unauthenticated SQL injection in Sangoma Switchvox (CVE-2026-9586) that can enable remote code execution; Horizon3 reported active attacks and CISA added it to KEV.

Threat actors have been exploiting an unauthenticated SQL injection in Sangoma Switchvox, tracked as CVE-2026-9586, cybersecurity firm Horizon3 reported on Tuesday. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday.

The flaw carries a CVSS score of 9.3 and exists in an endpoint that processes XML content. Researchers found the code concatenated a user-controlled PhoneIP value directly into PostgreSQL queries without sanitization or parameterization. A single crafted request can execute arbitrary SQL against the backend database and may lead to remote code execution. A NIST advisory states: “An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.”

Horizon3 published indicators of compromise to help organizations detect whether systems have been targeted and reported evidence of active exploitation in the wild.

CISA added CVE-2026-9586 to its KEV list alongside six other vulnerabilities, including issues affecting JFrog Artifactory, SonicWall SMA1000 appliances, the Starlette ASGI framework (CVE-2026-48710), the Kestra orchestration platform (CVE-2026-49869), and LiteLLM (CVE-2026-59822). The agency directed federal civilian agencies to apply patches for the listed vulnerabilities within three days, while the Starlette and Kestra flaws were given a two-week remediation window consistent with BOD 26-04.

Sangoma Switchvox is an enterprise VoIP telephony management product used to manage phone systems and call routing. An unauthenticated SQL injection that enables remote code execution can expose call records and configuration data, and may allow attackers to take control of appliance functions. Horizon3’s published indicators are intended to assist incident responders and defenders in identifying intrusions.

Organizations running Switchvox are advised to review the published advisories and indicators and apply available patches or mitigations promptly. CISA’s KEV listing sets a federal remediation priority for the vulnerability.

Articles by this author