Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

By George Bailey   Published: 09/02/26   Updated: 09/02/26   2 min read
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

What Changed

BleepingComputer reports that attackers are actively exploiting CVE-2026-9586, the most serious of 12 flaws Horizon3 discovered in Sangoma Switchvox and reported on April 10. Sangoma fixed the issue in version 8.4.0.2 on July 14.

The vulnerable path sits in the /pa HTTP endpoint, which parses XML messages used to notify other phone systems about call events. Horizon3 says the PhoneIP field is concatenated directly into an unparameterized SQL query, allowing a crafted XML request to trigger unauthenticated SQL injection and remote command execution.

Why This Matters Operationally

The real issue is not just that a VoIP management platform has an RCE path. Switchvox is used to configure and monitor business phone systems, which means compromise can land inside a communications system that often has weaker scrutiny than more obvious identity or server infrastructure.

Horizon3's honeypots observed exploitation on August 30 from a single source IP, 176.65.148.184, with the attacker attempting to establish a reverse shell, collect process data from the device, and exfiltrate it in base64-encoded form. That behavior makes this a concrete intrusion-review story, not just a patching reminder.

What Defenders Should Verify First

Source Context

CyberExperts used BleepingComputer's reporting and the Horizon3 research it cites to preserve the details that change response behavior: the /pa endpoint, the PhoneIP injection path, the fixed version 8.4.0.2, the observed attacker IP and port, and the warning that most exposed Switchvox systems are likely to be or already have been targeted.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading