Sangoma Switchvox Vulnerabilities Exploited in the Wild: Security Risks Revealed
Cybercriminals have actively exploited a critical-severity flaw in the enterprise VoIP telephony management system Sangoma Switchvox, according to warnings from Horizon3 and the Cybersecurity and Infrastructure Security Agency (CISA).
Vulnerability Details
The vulnerability, designated CVE-2026-9586 with a CVSS score of 9.3, is classified as an unauthenticated SQL injection vulnerability. It allows attackers to execute arbitrary code remotely by manipulating an endpoint that processes XML data. The flaw arises from the lack of input sanitization or parameterization when the user-controlled PhoneIP value is integrated into PostgreSQL queries.
CVE-2026-9586: Critical SQL Injection Flaw
A National Institute of Standards and Technology (NIST) advisory highlighted that an unauthenticated remote attacker could execute arbitrary SQL commands against the backend PostgreSQL database through a single malicious request. This includes performing database operations and achieving remote code execution.
CISA and Horizon3 Warnings
Horizon3 reported that threat actors have been leveraging CVE-2026-9586 in active attacks since early June, providing indicators of compromise (IoCs) to assist organizations in detecting potential breaches. CISA confirmed the vulnerability’s exploitation and included it in its Known Exploited Vulnerabilities (KEV) catalog on Wednesday.
Other Vulnerabilities in KEV Catalog
Alongside CVE-2026-9586, six other flaws were added, including a JFrog Artifactory vulnerability, two zero-day flaws in SonicWall SMA1000 devices, and others. The KEV list also features CVE-2026-48710, a high-severity HTTP request/response smuggling flaw in the Starlette ASGI framework, which has been targeted since May.
Recent Cybersecurity Developments
Another entry, CVE-2026-49869, is a critical command injection vulnerability in the open-source orchestration platform Kestra, disclosed in June and flagged as exploited by Microsoft. The final addition, CVE-2026-59822, is a high-severity authentication bypass in LiteLLM, with Wiz reporting exploit attempts targeting it via honeypots.
CISA Patching Requirements
CISA has mandated that federal agencies address these vulnerabilities within three days, except for the Kestra and Starlette flaws, which require patching within two weeks. This aligns with the requirements of BOD 26-04.
Broader Cybersecurity Landscape
Other recent cybersecurity developments include the exposure of over 153 million driver license images on the dark web, the discovery of exploit activity targeting a critical Langflow vulnerability, and the disruption of the 23-year-old Sality P2P botnet. Additionally, researchers identified a 12-year-old PostgreSQL vulnerability enabling database and server takeovers, while major software updates from Chrome, Firefox, and VMware addressed multiple critical flaws.
The cybersecurity landscape continues to evolve as threat actors exploit newly disclosed vulnerabilities, underscoring the urgency for organizations to implement timely patching and monitoring strategies.
