Particle.news

Attackers Actively Exploiting Critical Sangoma Switchvox SQL Injection

Unauthenticated exploitation can run database and operating-system commands that let attackers steal signing keys and maintain access to business phone systems.

Overview

  • Honeypot telemetry showed active exploitation beginning Sunday, Aug. 30, with a single observed source IP dropping reverse shells and running encoded reconnaissance before exfiltrating data.
  • The flaw, tracked as CVE-2026-9586 and rated CVSS 9.3, is an unauthenticated SQL injection in Switchvox’s /pa XML endpoint that concatenates the PhoneIP value into unparameterized PostgreSQL queries and can lead to remote code execution.
  • Sangoma issued a patch on July 14 in Switchvox 8.4.0.2 that fixes the vulnerability and administrators are urged to upgrade immediately or isolate the management interface and /pa endpoint if they cannot patch.
  • Indicators of compromise include suspicious entries in /var/log/switchvox/db-quirks.log and network connections to 176.65.148.184, notably on port 39323, and defenders should hunt for base64-encoded exfiltration and reverse-shell artifacts.
  • About 4,000 Switchvox instances are exposed on the internet, mostly in the U.S., which raises the risk that small and mid-sized businesses could face stolen keys, forged authentication and persistent compromise if they remain unpatched.