
What Changed
BleepingComputer reports that attackers are actively exploiting CVE-2026-9586, the most serious of 12 flaws Horizon3 discovered in Sangoma Switchvox and reported on April 10. Sangoma fixed the issue in version 8.4.0.2 on July 14.
The vulnerable path sits in the /pa HTTP endpoint, which parses XML messages used to notify other phone systems about call events. Horizon3 says the PhoneIP field is concatenated directly into an unparameterized SQL query, allowing a crafted XML request to trigger unauthenticated SQL injection and remote command execution.
Why This Matters Operationally
The real issue is not just that a VoIP management platform has an RCE path. Switchvox is used to configure and monitor business phone systems, which means compromise can land inside a communications system that often has weaker scrutiny than more obvious identity or server infrastructure.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Built from 100+ trusted cybersecurity sources.
Built from 100+ trusted cybersecurity sources.
Horizon3's honeypots observed exploitation on August 30 from a single source IP, 176.65.148.184, with the attacker attempting to establish a reverse shell, collect process data from the device, and exfiltrate it in base64-encoded form. That behavior makes this a concrete intrusion-review story, not just a patching reminder.
What Defenders Should Verify First
- Identify every Sangoma Switchvox deployment and confirm whether any internet-exposed instance is still below version 8.4.0.2.
- Inspect
/var/log/switchvox/db-quirks.logfor suspicious SQL-related entries and review network logs for connections to176.65.148.184, especially on port39323. - Treat the issue as a likely mass-targeting problem if the system is internet reachable. Horizon3 says Shodan shows roughly
4,000exposed devices, most in the United States. - Review administrative activity, outbound connections, and any unusual process or shell activity on affected appliances before assuming patching alone closes the story.
Source Context
CyberExperts used BleepingComputer's reporting and the Horizon3 research it cites to preserve the details that change response behavior: the /pa endpoint, the PhoneIP injection path, the fixed version 8.4.0.2, the observed attacker IP and port, and the warning that most exposed Switchvox systems are likely to be or already have been targeted.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief